PT-2025-31059 · Optimizely · Episerver Cms
F. Beie
+1
·
Published
2025-07-28
·
Updated
2025-07-29
·
CVE-2025-27802
4.8
Medium
Base vector | Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Episerver CMS versions prior to 11.21.4 and prior to 11.37.5
Episerver CMS versions prior to 12.22.1 and prior to 11.37.3
Description:
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim’s browser. RTE properties (text fields) within the "Edit" section of the CMS allowed the input of arbitrary text, enabling the injection of malicious JavaScript code that would execute when a user previews the page. An attacker needed at least the "WebEditor" role to exploit this issue.
Recommendations:
Episerver CMS versions prior to 11.21.4: Update to version 11.21.4 or later.
Episerver CMS versions prior to 11.37.5: Update to version 11.37.5 or later.
Episerver CMS versions prior to 12.22.1: Update to version 12.22.1 or later.
Episerver CMS versions prior to 11.37.3: Update to version 11.37.3 or later.
Fix
XSS
Weakness Enumeration
Related Identifiers
Affected Products
References · 10
- https://api.nuget.optimizely.com/packages/episerver.cms.core/12.22.1# · Patch
- https://support.optimizely.com/hc/en-us/articles/30886353301645-2025-Optimizely-CMS-11-PaaS-release-notes#h_01K09MR1SZS4FEAPD4478GQ0FR · Patch
- https://api.nuget.optimizely.com/packages/episerver.cms.core/11.21.4# · Patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-27802 · Security Note
- https://support.optimizely.com/hc/en-us/articles/37757063222029-2024-Optimizely-CMS-12-PaaS-release-notes#h_01JN4AZV48WKNADH3KWC2GYDS5 · Patch
- https://r.sec-consult.com/optimizely · Note
- https://twitter.com/CVEnew/status/1949762893605380422 · Twitter Post
- https://t.me/CVEtracker/28547 · Telegram Post
- https://twitter.com/autumn_good_35/status/1950122869540655417 · Twitter Post
- https://twitter.com/VulmonFeeds/status/1949770301488685177 · Twitter Post