CVE-2025-34511 is an unrestricted file upload vulnerability in Sitecore PowerShell Extensions, affecting Sitecore Experience Manager, Experience Platform, Experience Commerce, and Managed Cloud up to version 7.0. A remote, authenticated attacker can exploit this flaw by uploading arbitrary files via crafted HTTP requests. This vulnerability carries a CVSS score of 8.8 (High), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability through remote code execution. While not yet in CISA's KEV catalog, a Metasploit module exists, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, <= 10.4CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 10.4CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* | ||
>= 9.0, < 10.4CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* | ||
10.4CPE matchmatch criteria | cpe:2.3:a:sitecore:experience_platform:10.4:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.