Rapid7

module

Sitecore XP CVE-2025-34510 Post-Authentication Remote Code Execution

Disclosed
Jun 17, 2025
Created
Sep 11, 2025

Description

This module exploits CVE-2025-34510, path traversal leading to remote code execution. The module exploits also CVE-2025-34509 - hardcoded credentials of ServicesAPI account - to gain foothold.

Authors

Piotr Bazydlo
msutovsky-r7

Platform

Windows

Architectures

x86, x64

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use exploit/windows/http/sitecore_xp_cve_2025_34510
msf exploit(sitecore_xp_cve_2025_34510) > show targets
...targets...
msf exploit(sitecore_xp_cve_2025_34510) > set TARGET < target-id >
msf exploit(sitecore_xp_cve_2025_34510) > show options
...show and set options...
msf exploit(sitecore_xp_cve_2025_34510) > exploit

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.