CVE-2025-22389
CVSS 3.1 Score 8 of 10 (high)
Details
Summary
CVE-2025-22389 is a medium-severity vulnerability affecting Optimizely EPiServer.CMS.Core before version 12.32.0. The issue lies in the CMS's failure to properly validate uploaded files. Malicious actors can exploit this vulnerability to upload potentially harmful file types, such as .docm and .html. Once these files are accessed by application users, they can be used to execute malicious actions or compromise users' systems. This vulnerability poses a significant risk to system security and should be addressed promptly by updating to the latest version of Optimizely EPiServer.CMS.Core.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.