Optimizely EPiServer CMS File Upload Validation Vulnerability Allowing Malicious File Execution
Vulnerability
A medium-severity vulnerability exists in Optimizely EPiServer.CMS.Core versions prior to 12.32.0. The issue arises because the application fails to properly validate uploaded files, allowing potentially harmful file types, such as .docm and .html, to be uploaded. When these files are accessed by application users, they can execute malicious actions or compromise users' systems.
Impact
Exploitation of this vulnerability could lead to the execution of malicious actions or compromise of users' systems through uploaded files.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.4exploitability
6.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
