Holm Security discovered a vulnerability in EPiServer’s SiteSeeker product. The vulnerability means that JavaScript in affected web pages can be modified to include malware from another seemingly trustworthy domain. EPiServer has been informed of the vulnerability and they have developed a hotfix for this vulnerability in EPiServer CMS version 11.0.1. EPiServer refers customers to “EPiServer internal ticket ID: ESEE-61”.
Some examples of affected web pages are: