CVE-2025-22383
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Jan 4, 2025
Updated: Jan 6, 2025
CWE ID 79
Summary
CVE-2025-22383 is a medium-severity input validation vulnerability discovered in Optimizely's Configured Commerce before 5.2.2408. This issue impacts the Commerce B2B application's Contact Us functionality. Visitors can exploit this weakness by sending e-mail messages containing unfiltered HTML markup in specific circumstances, posing a potential security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.