Rapid7

module

Sitecore XP CVE-2025-34511 Post-Authentication File Upload

Disclosed
Jun 17, 2025
Created
Sep 11, 2025

Description

This module exploits CVE-2025-34511, a file upload vulnerability in PowerShell extensions. The module exploits also CVE-2025-34509 - hardcoded credentials of ServicesAPI account - to gain foothold.

Authors

Piotr Bazydlo
msutovsky-r7

Platform

Windows

Architectures

x86, x64

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use exploit/windows/http/sitecore_xp_cve_2025_34511
msf exploit(sitecore_xp_cve_2025_34511) > show targets
...targets...
msf exploit(sitecore_xp_cve_2025_34511) > set TARGET < target-id >
msf exploit(sitecore_xp_cve_2025_34511) > show options
...show and set options...
msf exploit(sitecore_xp_cve_2025_34511) > exploit

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.