Optimizely EPiServer CMS Password Complexity Vulnerability
Vulnerability
A medium-severity vulnerability exists in Optimizely EPiServer.CMS.Core versions prior to 12.32.0, due to inadequate enforcement of password complexity requirements. The application allows users to create passwords with a minimum length of 6 characters, but these passwords lack the necessary complexity to withstand contemporary attack methods such as password spraying or offline cracking.
Impact
The vulnerability could lead to weaker password security, making it easier for attackers to compromise accounts using password spraying or offline cracking techniques.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
7.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
