CVE-2025-27802 (CNNVD-202507-3494)
中文标题:
Optimizely Episerver Content Management System 安全漏洞
英文标题:
Stored Cross-Site Scripting in Episerver Content Management System (CMS) Edit Preview
漏洞描述
中文描述:
Optimizely Episerver Content Management System是美国Optimizely公司的一个企业级内容管理系统。 Optimizely Episerver Content Management System存在安全漏洞,该漏洞源于存储型跨站脚本使经过身份验证的攻击者能执行恶意JavaScript代码。
英文描述:
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. RTE properties (text fields), which could be used in the "Edit" section of the CMS, allowed the input of arbitrary text. It was possible to input malicious JavaScript code in these properties that would be executed if a user visits the previewed page. Attackers needed at least the role "WebEditor" in order to exploit this issue. Affected products: Version 11.X: EPiServer.CMS.Core (<11.21.4) with EPiServer.CMS.UI (<11.37.5), Version 12.X: EPiServer.CMS.Core (<12.22.1) with EPiServer.CMS.UI (<11.37.3)
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Optimizely | Episerver Content Management System (CMS) | - | < 11.21.4 | - |
cpe:2.3:a:optimizely:episerver_content_management_system_(cms):*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:L/SC:L/SI:L/SA:N
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-27802 |
2025-11-11 15:23:12 | 2025-11-11 07:40:19 |
| NVD | nvd_CVE-2025-27802 |
2025-11-11 15:00:57 | 2025-11-11 07:48:09 |
| CNNVD | cnnvd_CNNVD-202507-3494 |
2025-11-11 15:12:51 | 2025-11-11 08:00:02 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202507-3494
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 1
- references_count: 3 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']