CVE-2025-34510: Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by sending a crafted HTTP request to upload a ZIP archive containing path traversal sequences, allowing arbitrary file writes and leading to code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34510?
CVE-2025-34510 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-34510?
To fix CVE-2025-34510, update Sitecore Experience Manager, Experience Platform, or Experience Commerce to a patched version released by Sitecore.
Who is affected by CVE-2025-34510?
CVE-2025-34510 affects users running Sitecore Experience Manager, Experience Platform, or Experience Commerce versions 9.0 through 9.3 and 10.0 through 10.4.
What type of vulnerability is CVE-2025-34510?
CVE-2025-34510 is classified as a Zip Slip vulnerability that can be exploited through crafted HTTP requests.
Can CVE-2025-34510 be exploited remotely?
Yes, CVE-2025-34510 can be exploited remotely by authenticated attackers.