CVE-2025-34511
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 22.32% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- sitecore/experience commerce · sitecore/experience manager · sitecore/experience platform · sitecore/managed cloud
- Source
- disclosure@vulncheck.com
References
- https://labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-experience-platform/Exploit, Third Party Advisory
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003667Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.