PT-2025-31057 · Optimizely · Episerver.Cms.Core+2

F. Beie

+1

·

Published

2025-07-28

·

Updated

2025-07-29

·

CVE-2025-27801

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Episerver CMS by Optimizely versions prior to 11.21.4 and prior to 11.37.5 Episerver CMS by Optimizely versions prior to 12.22.1 and prior to 11.37.3
Description The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReference properties, which could be used in the "Edit" section of the CMS, offered an upload functionality for documents. These documents could later be used as displayed content on the page. It was possible to upload SVG files that include malicious JavaScript code that would be executed if a user visited the direct URL of the preview image. Attackers needed at least the role "WebEditor" in order to exploit this issue.
Recommendations Update EPiServer.CMS.Core to version 11.21.4 or later. Update EPiServer.CMS.UI to version 11.37.5 or later. Update EPiServer.CMS.Core to version 12.22.1 or later. Update EPiServer.CMS.UI to version 11.37.3 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-27801

Affected Products

Episerver.Cms.Core
Episerver.Cms.Ui
Episerver Cms