We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-34511

Sitecore PowerShell Extension RCE via Unrestricted Upload



Description

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.

Reserved 2025-04-15 | Published 2025-06-17 | Updated 2025-06-17 | Assigner VulnCheck


HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

Any version
affected

Credits

Piotr Bazydlo of watchTowr finder

References

labs.watchtowr.com/...chain-in-sitecore-experience-platform/ third-party-advisory exploit technical-description

cve.org (CVE-2025-34511)

nvd.nist.gov (CVE-2025-34511)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-34511

Support options

Helpdesk Chat, Email, Knowledgebase