ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Chained Flaws in Enterprise CMS Provider Sitecore Could Allow RCE

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-34511
+2 in the same advisory: …34510 …34509
Unrestricted File Upload RCE in Sitecore PowerShell Extensions (SPE)

Sitecore PowerShell Extensions (SPE), a widely installed administrative add-on for Sitecore Experience Manager (XM) and Experience Platform (XP), contains an unrestricted file upload flaw (CWE-434) in all versions through 7.0. A remote attacker with valid low-privileged credentials can send a crafted HTTP request that uploads arbitrary files, such as a webshell, to the web server, which are then executed, yielding remote code execution with high impact on confidentiality, integrity, and availability. Any Sitecore XM, XP, Experience Commerce, or Managed Cloud deployment running the SPE add-on at version 7.0 or earlier is affected, making enterprise CMS operators the primary at-risk population. Exploitation is not yet listed in CISA KEV and no confirmed in-the-wild campaigns are documented, but a public proof-of-concept has been published by WatchTowr, and EPSS assigns a high 22.3% probability of exploitation within 30 days (98th percentile). Researchers have also shown this flaw chained with other Sitecore issues, including a hard-coded credential, to achieve pre-authentication RCE in enterprise deployments.

Do: Upgrade Sitecore PowerShell Extensions to a fixed release newer than 7.0 as directed by Sitecore's advisory, prioritizing internet-facing content management and delivery servers. Until patched, restrict access to SPE endpoints (PowerShell services/remoting endpoints) to trusted administrative users with strong authentication. Audit upload directories and web roots for unexpected files or webshells, and confirm the instance is also patched against the related hard-coded-credential Sitecore XP issues researchers chained with this flaw.

8.8
group max
22% PoC
  • Sitecore PowerShell Extensions (SPE) add-on all versions through 7.0 (7.0 and earlier)
  • Sitecore Experience Manager (XM) with SPE add-on installed any XM deployment running SPE 7.0 or earlier
  • Sitecore Experience Platform (XP) with SPE add-on installed any XP deployment running SPE 7.0 or earlier
  • +2 more
largetens of thousands of internet-exposed Sitecore XM/XP/Commerce instances, with a large but unquantified subset running the SPE add-on (exact SPE install count…
Full article511 words · extracted from infosecurity-magazine.com · click to collapse

Vulnerability research firm WatchTowr has detected seven vulnerabilities in Sitecore, a popular content management system (CMS) provider used by HSBC, United Airlines, P&G and L’Oréal.

In its first report, published on June 17, WatchTowr shared findings about three vulnerabilities that could allow an unauthenticated attacker to perform a complete remote code execution (RCE) on the Sitecore Experience Platform version 10.4.1.

The report highlighted the extent of access that a simple password enables and how chaining it with two post-authentication RCE vulnerabilities allows bad actors to establish a complete pre-authentication RCE chain. 

One-Letter Password By Default

WatchTowr detected the vulnerabilities on February 28, 2025, notified Sitecore and then searched through client attack surfaces for impacted systems and communicated with those affected.

The firm has identified at least 22,000 exposed instances, but estimates that the actual number is significantly higher.

Speaking to Infosecurity, Benjamin Harris, CEO and Founder of WatchTowr, explained how his team found the flaws: “By default, recent versions of Sitecore shipped to users that had a hardcoded password of ‘b’. It’s 2025, and we can’t believe we still have to say this, but that’s very bad. WatchTowr chained this with two post-auth RCEs to achieve full pre-auth RCE on the latest versions of Sitecore (patched only after our disclosure).”

The three vulnerabilities are tracked by WatchTowr as follows:

  • WT-2025-0024: Hardcoded Credentials
  • WT-2025-0032: Post-Auth RCE (Via Path Traversal)
  • WT-2025-0025: Post-Auth RCE (Via Sitecore PowerShell Extension)

They haven’t yet been attributed CVE identifiers, but WatchTowr believes Sitecore will assign CVE identifiers on June 17.

The flaws were patched in Sitecore Experience Platform’s latest version on May 11. The software provider published a security advisory on June 16 with details of patches and steps to remediate.

On May 29, WatchTowr and Sitecore agreed to hold off with the public disclosure until June 17.

No CVE records have been publicly disclosed at the time of writing.

A Popular CMS Provider for Large Enterprises

Harris emphasized that the Sitecore CMS is deployed across thousands of environments, including banks, airlines and global enterprises, suggesting that if exploited, these chained vulnerabilities could have a significant impact on Sitecore customers.

“And no, this isn’t theoretical: we’ve run the full chain, end-to-end. If you’re running Sitecore, it doesn’t get worse than this - rotate credentials and patch immediately before attackers inevitably reverse engineer the fix,” Harris concluded.

WatchTowr said it will disclose four additional vulnerabilities in Sitecore’s products in an upcoming report.

Update: CVEs Assigned

Speaking to Infosecurity, Sitecore confirmed on June 18 that the three vulnerabilities have been assigned CVE identifiers by VulnCheck:

  • WT-2025-0024 - Hardcoded Credentials: CVE-2025-34509
  • WT-2025-0032 - Post-Auth RCE (Via Path Traversal): CVE-2025-34510
  • WT-2025-0025 - Post-Auth RCE (Via Sitecore PowerShell Extension): CVE-2025-34511

"Our customer support teams have proactively communicated these updates to our affected clients. All impacted SaaS products have been remediated, and we strongly advise in-scope on-premises customers to promptly apply the provided patches," a Sitecore spokesperson told Infosecurity.

This article was updated on June 19 to mention Sitecore's security advisory and add the CVE identifiers for the three vulnerabilities.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chained-flaws-cms-sitecore-rce/