Metrics
Affected Vendors & Products
Tue, 29 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 29 Jul 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 29 Jul 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Episerver
Episerver episerver Episerver episerver Cms |
|
Vendors & Products |
Episerver
Episerver episerver Episerver episerver Cms |
Mon, 28 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Jul 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 28 Jul 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. The Admin dashboard offered the functionality to add gadgets to the dashboard. This included the "Notes" gadget. An authenticated attacker with the corresponding access rights (such as "WebAdmin") that was impersonating the victim could insert malicious JavaScript code in these notes that would be executed if the victim visited the dashboard. Affected products: Version 11.X: EPiServer.CMS.Core (<11.21.4) with EPiServer.CMS.UI (<11.37.5), Version 12.X: EPiServer.CMS.Core (<12.22.1) with EPiServer.CMS.UI (<11.37.3) | |
Title | Stored Cross-Site Scripting in Episerver Content Management System (CMS) Admin Dashboard | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: SEC-VLab
Published: 2025-07-28T08:33:24.304Z
Updated: 2025-07-29T09:36:10.631Z
Reserved: 2025-03-07T06:46:34.308Z
Link: CVE-2025-27800

Updated: 2025-07-28T16:53:57.236Z

Status : Awaiting Analysis
Published: 2025-07-28T09:15:34.387
Modified: 2025-07-29T14:14:29.590
Link: CVE-2025-27800

No data.