Vulnerability Description
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sitecore | Experience Commerce | >= 9.0, <= 10.4 |
| Sitecore | Experience Manager | >= 9.0, <= 10.4 |
| Sitecore | Experience Platform | >= 9.0, < 10.4 |
| Sitecore | Managed Cloud | - |
Related Weaknesses (CWE)
References
- https://labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-expeExploitThird Party Advisory
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003667Vendor Advisory
FAQ
What is CVE-2025-34511?
CVE-2025-34511 is a vulnerability with a CVSS score of 8.8 (HIGH). Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authentica...
How severe is CVE-2025-34511?
CVE-2025-34511 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-34511?
Check the references section above for vendor advisories and patch information. Affected products include: Sitecore Experience Commerce, Sitecore Experience Manager, Sitecore Experience Platform, Sitecore Managed Cloud.