CVE-2025-22388

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:optimizely:optimizely_cms:*:*:*:*:*:*:*:*

History

20 May 2025, 20:11

Type Values Removed Values Added
First Time Optimizely
Optimizely optimizely Cms
CWE CWE-79
CPE cpe:2.3:a:optimizely:optimizely_cms:*:*:*:*:*:*:*:*
References () https://support.optimizely.com/hc/en-us/articles/33182047260557-Content-Management-System-CMS-Security-Advisory-CMS-2025-01 - () https://support.optimizely.com/hc/en-us/articles/33182047260557-Content-Management-System-CMS-Security-Advisory-CMS-2025-01 - Vendor Advisory

04 Jan 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-04 02:15

Updated : 2025-05-20 20:11


NVD link : CVE-2025-22388

Mitre link : CVE-2025-22388


JSON object : View

Products Affected

optimizely

  • optimizely_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')