CVE-2025-34097 is an unrestricted file upload vulnerability in ProcessMaker versions prior to 3.5.4, allowing an authenticated administrator to upload malicious PHP code via a crafted plugin archive. This high-severity flaw (CVSS 8.6) enables remote code execution on the server with web server user privileges, with potential for full compromise, especially when chained with CVE-2022-38577. While not actively exploited in the wild, a Metasploit module exists, and the vulnerability has significant community discussion, indicating high interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ProcessMaker Inc. | ProcessMaker | >= 0, < 3.5.4CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.