Wiz Agents & Workflows are here

CVE-2025-34510
Sitecore Experience Platform (XP) vulnerability analysis and mitigation

Overview

CVE-2025-34510 is a path traversal vulnerability (CWE-23) affecting Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4. The vulnerability was disclosed on June 17, 2025, and received a CVSS v3.1 base score of 8.8 (HIGH). A remote, authenticated attacker can exploit this issue by sending crafted HTTP requests to upload ZIP archives containing path traversal sequences, allowing arbitrary file writes and leading to code execution (NVD, Wiz Report).

Technical details

The vulnerability is classified as a Zip Slip vulnerability that exists in the upload functionality of the platform. It can be triggered through the '/sitecore/shell/Applications/Dialogs/Upload/Upload2.aspx' endpoint by uploading specially crafted ZIP files. The CVSS vector string is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and requires low privileges (Watchtowr Labs, Wiz Report).

Impact

Successful exploitation of this vulnerability allows attackers to achieve arbitrary file writes and ultimately execute code on the affected system. The vulnerability can potentially compromise the confidentiality, integrity, and availability of the system with high impact. Given Sitecore's deployment across thousands of environments, including banks, airlines, and global enterprises, the potential impact radius is significant (Hacker News, Wiz Report).

Mitigation and workarounds

Sitecore has released patches for the affected versions and published details in their knowledge base article. The company has remediated all impacted SaaS products and strongly advises in-scope on-premises customers to promptly apply the provided patches. Organizations running affected versions should upgrade to the patched versions as soon as possible (Hacker News).

Community reactions

Security researchers and industry experts have expressed significant concern about the vulnerability. Benjamin Harris, CEO and founder of watchTowr, emphasized the severity of the issue, stating 'Sitecore is deployed across thousands of environments, including banks, airlines, and global enterprises – so the blast radius here is massive.' Sitecore has acknowledged the vulnerability and actively collaborated with researchers to address the issue (Hacker News).

Additional resources


SourceThis report was generated using AI

Related Sitecore Experience Platform (XP) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53693CRITICAL9.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-53690CRITICAL9
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
YesNoSep 03, 2025
CVE-2025-53691HIGH8.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-53694HIGH7.5
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2022-4979MEDIUM5.1
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoJul 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management