An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, including .docm .html. When accessed by application users, these files can be used to execute malicious actions or compromise users' systems.
References
Configurations
No configuration.
History
11 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
04 Jan 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 |
04 Jan 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-04 02:15
Updated : 2025-02-11 22:15
NVD link : CVE-2025-22389
Mitre link : CVE-2025-22389
CVE.ORG link : CVE-2025-22389
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type