ZeroHour

CVE-2025-34511

PoC large

Unrestricted File Upload RCE in Sitecore PowerShell Extensions (SPE)

CVSS 3.1
8.8 high
EPSS
22%p98
Published
()
Modified
AI analysis

Sitecore PowerShell Extensions (SPE), a widely installed administrative add-on for Sitecore Experience Manager (XM) and Experience Platform (XP), contains an unrestricted file upload flaw (CWE-434) in all versions through 7.0. A remote attacker with valid low-privileged credentials can send a crafted HTTP request that uploads arbitrary files, such as a webshell, to the web server, which are then executed, yielding remote code execution with high impact on confidentiality, integrity, and availability. Any Sitecore XM, XP, Experience Commerce, or Managed Cloud deployment running the SPE add-on at version 7.0 or earlier is affected, making enterprise CMS operators the primary at-risk population. Exploitation is not yet listed in CISA KEV and no confirmed in-the-wild campaigns are documented, but a public proof-of-concept has been published by WatchTowr, and EPSS assigns a high 22.3% probability of exploitation within 30 days (98th percentile). Researchers have also shown this flaw chained with other Sitecore issues, including a hard-coded credential, to achieve pre-authentication RCE in enterprise deployments.

What to do: Upgrade Sitecore PowerShell Extensions to a fixed release newer than 7.0 as directed by Sitecore's advisory, prioritizing internet-facing content management and delivery servers. Until patched, restrict access to SPE endpoints (PowerShell services/remoting endpoints) to trusted administrative users with strong authentication. Audit upload directories and web roots for unexpected files or webshells, and confirm the instance is also patched against the related hard-coded-credential Sitecore XP issues researchers chained with this flaw.

Affected
Sitecore PowerShell Extensions (SPE) add-onall versions through 7.0 (7.0 and earlier)
Sitecore Experience Manager (XM) with SPE add-on installedany XM deployment running SPE 7.0 or earlier
Sitecore Experience Platform (XP) with SPE add-on installedany XP deployment running SPE 7.0 or earlier
Sitecore Experience Commerce with SPE add-on installedany deployment running SPE 7.0 or earlier
Sitecore Managed Cloud with SPE add-on installedany Managed Cloud deployment running SPE 7.0 or earlier
Estimated exposure
largetens of thousands of internet-exposed Sitecore XM/XP/Commerce instances, with a large but unquantified subset running the SPE add-on (exact SPE install count… — Public internet scans and vendor reporting consistently show tens of thousands of Sitecore XP/XM instances exposed online across enterprise (government, finance, retail) deployments, and SPE is a very commonly installed administration…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.

Vendors
sitecore
Products
experience commerce, experience manager, experience platform, managed cloud
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news