CVE-2025-22389

CVSS 3.1 Score 8 of 10 (high)

Details

Published Jan 4, 2025
Updated: Feb 11, 2025
CWE ID 434

Summary

CVE-2025-22389 is a medium-severity vulnerability affecting Optimizely EPiServer.CMS.Core before version 12.32.0. The issue lies in the CMS's failure to properly validate uploaded files. Malicious actors can exploit this vulnerability to upload potentially harmful file types, such as .docm and .html. Once these files are accessed by application users, they can be used to execute malicious actions or compromise users' systems. This vulnerability poses a significant risk to system security and should be addressed promptly by updating to the latest version of Optimizely EPiServer.CMS.Core.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share