CVE-2025-34511: Sitecore PowerShell Extension RCE via Unrestricted Upload
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34511?
CVE-2025-34511 has a high severity rating due to the potential for remote file uploads by an authenticated attacker.
How do I fix CVE-2025-34511?
To mitigate CVE-2025-34511, upgrade your Sitecore PowerShell Extensions to version 7.1 or later.
What type of vulnerability is CVE-2025-34511?
CVE-2025-34511 is categorized as an unrestricted file upload vulnerability.
Who is affected by CVE-2025-34511?
CVE-2025-34511 affects Sitecore PowerShell Extensions versions up to and including 7.0.
Can CVE-2025-34511 lead to further attacks?
Yes, CVE-2025-34511 can allow attackers to upload arbitrary files, potentially leading to remote code execution and other exploits.