CVE-2025-34511
PoC largeUnrestricted File Upload RCE in Sitecore PowerShell Extensions (SPE)
Sitecore PowerShell Extensions (SPE), a widely installed administrative add-on for Sitecore Experience Manager (XM) and Experience Platform (XP), contains an unrestricted file upload flaw (CWE-434) in all versions through 7.0. A remote attacker with valid low-privileged credentials can send a crafted HTTP request that uploads arbitrary files, such as a webshell, to the web server, which are then executed, yielding remote code execution with high impact on confidentiality, integrity, and availability. Any Sitecore XM, XP, Experience Commerce, or Managed Cloud deployment running the SPE add-on at version 7.0 or earlier is affected, making enterprise CMS operators the primary at-risk population. Exploitation is not yet listed in CISA KEV and no confirmed in-the-wild campaigns are documented, but a public proof-of-concept has been published by WatchTowr, and EPSS assigns a high 22.3% probability of exploitation within 30 days (98th percentile). Researchers have also shown this flaw chained with other Sitecore issues, including a hard-coded credential, to achieve pre-authentication RCE in enterprise deployments.
What to do: Upgrade Sitecore PowerShell Extensions to a fixed release newer than 7.0 as directed by Sitecore's advisory, prioritizing internet-facing content management and delivery servers. Until patched, restrict access to SPE endpoints (PowerShell services/remoting endpoints) to trusted administrative users with strong authentication. Audit upload directories and web roots for unexpected files or webshells, and confirm the instance is also patched against the related hard-coded-credential Sitecore XP issues researchers chained with this flaw.
| Sitecore PowerShell Extensions (SPE) add-on | all versions through 7.0 (7.0 and earlier) |
| Sitecore Experience Manager (XM) with SPE add-on installed | any XM deployment running SPE 7.0 or earlier |
| Sitecore Experience Platform (XP) with SPE add-on installed | any XP deployment running SPE 7.0 or earlier |
| Sitecore Experience Commerce with SPE add-on installed | any deployment running SPE 7.0 or earlier |
| Sitecore Managed Cloud with SPE add-on installed | any Managed Cloud deployment running SPE 7.0 or earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
- Vendors
- sitecore
- Products
- experience commerce, experience manager, experience platform, managed cloud
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H