An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.
History

Mon, 06 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 04 Jan 2025 02:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-04T00:00:00

Updated: 2025-01-06T15:11:11.504Z

Reserved: 2025-01-04T00:00:00

Link: CVE-2025-22388

cve-icon Vulnrichment

Updated: 2025-01-06T15:03:49.172Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-04T02:15:07.480

Modified: 2025-01-06T15:15:16.307

Link: CVE-2025-22388

cve-icon Redhat

No data.