- Description
- An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.
- Source
- cve@mitre.org
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 5.7
- Impact score
- 3.6
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- cve@mitre.org
- CWE-79
- Hype score
- Not currently trending
CVE-2025-22388 An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing m… https://t.co/mZ41lwE5SW
@CVEnew
4 Jan 2025
550 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-22388 Stored Cross-Site Scripting Vulnerability in Optimizely EPiServer CMS An issue was found in Optimizely EPiServer.CMS.Core before version 12.22.0. There is a serious Stored Cross-Site Scripting (XSS... https://t.co/qyIWJz4obg
@VulmonFeeds
4 Jan 2025
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes