Insufficient Password Complexity in Optimizely CMS
CVE-2025-22390

Currently unrated

Key Information:

Vendor

Optimizely

Vendor
CVE Published:
4 January 2025

What is CVE-2025-22390?

A significant vulnerability in the Optimizely EPiServer.CMS.Core product has been identified, stemming from inadequate enforcement of password complexity requirements. The system allows users to create passwords with a minimum length of only 6 characters, which does not meet current security standards. This limitation exposes the application to various attack vectors, including password spraying and offline password cracking techniques that could compromise user accounts and sensitive data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.