High severity8.8NVD Advisory· Published Jun 17, 2025· Updated Jun 17, 2026
CVE-2025-34511
CVE-2025-34511
Description
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*Range: >=9.0,<=10.4
cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:*range: >=9.0,<10.4
- cpe:2.3:a:sitecore:experience_platform:10.4:-:*:*:*:*:*:*
- cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:*
<=7.0+ 1 more
- (no CPE)range: <=7.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-experience-platform/nvdExploitThird Party Advisory
- support.sitecore.com/kbnvdVendor Advisory
News mentions
0No linked articles in our index yet.