PT-2025-31059 · Optimizely · Episerver Cms
F. Beie
+1
·
Published
2025-07-28
·
Updated
2025-07-29
·
CVE-2025-27802
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Episerver CMS versions prior to 11.21.4 and prior to 11.37.5
Episerver CMS versions prior to 12.22.1 and prior to 11.37.3
Description
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim’s browser. RTE properties (text fields) within the "Edit" section of the CMS allowed the input of arbitrary text, enabling the injection of malicious JavaScript code that would execute when a user previews the page. An attacker needed at least the "WebEditor" role to exploit this issue.
Recommendations
Episerver CMS versions prior to 11.21.4: Update to version 11.21.4 or later.
Episerver CMS versions prior to 11.37.5: Update to version 11.37.5 or later.
Episerver CMS versions prior to 12.22.1: Update to version 12.22.1 or later.
Episerver CMS versions prior to 11.37.3: Update to version 11.37.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Episerver Cms