Jens Nygård
Jan 10, 2012
visibility 18673
star star star star star
(2 votes)

Security vulnerability - Elevation of privilege

A security vulnerability has been detected which allows elevation of privilege for a user that has access to Edit mode in EPiServer CMS 5 and CMS 6. In practice this means that someone with editorial privileges could take ownership of the “WebAdmins” account.

Websites based on EPiServer CMS 5 and 6 using Forms Authentication with a Membership provider that supports updating are affected by this security vulnerability. Websites using Windows Authentication or Forms Authentication with Windows Membership provider are not affected.

We recommend our partners to contact EPiServer Developer Support to obtain a hotfix for the CMS specific security concerns.

The above shares some characteristics with the vulnerability previously reported by Microsoft, but should not be mistaken as the same. For more information see Microsoft Security Bulletin MS11-100

Jan 10, 2012

Comments

Magnus Rahl
Magnus Rahl Jan 10, 2012 06:55 PM

I assume this includes CMS 6 R2?

Lars Bodahl
Lars Bodahl Jan 10, 2012 10:44 PM

All CMS 5 and 6 versions. You get a hotfix from support :)

erik.engstrand@precio.se
erik.engstrand@precio.se Jan 11, 2012 09:05 AM

Thanx

error Please login to comment.
Latest blogs
Two more database surprises when upgrading from CMS 11 to CMS 13

Back in June I wrote about four database surprises when upgrading from CMS 11 to CMS 13 ( old post ). Here are two more, found on another CMS 11...

Per Nergård (MVP) | Sep 8, 2026

WebMCP providing understandable actions to agents in Optimizely

WebMCP is coming to Optimizely: a strategic view for CMS and Commerce teams At Opticon 2026 in New York, Alex Atzberger framed Optimizely's strateg...

Scott Reed | Sep 8, 2026

The Optimizely SaaS CMS Administrator Certification: More Than an Admin Exam

When I started preparing for the Optimizely SaaS CMS Administrator Certification, I expected most of the material to focus on administrative work:...

Augusto Davalos | Sep 8, 2026

Two Machines, One Memory

How to keep a Claude Code memory store in lockstep across two machines, using nothing but git and two hooks. We've been running Claude Code against...

KennyG | Sep 7, 2026