PT-2025-25745 · Sitecore · Sitecore Experience Manager+1
Piotr Bazydlo
·
Published
2025-02-28
·
Updated
2025-12-27
·
CVE-2025-34509
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 through 10.1.4 rev. 011974 PRE
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.2
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.3 through 10.3.3 rev. 011967 PRE
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.4 through 10.4.1 rev. 011941 PRE
Description
The affected software contains a hardcoded user account. Unauthenticated and remote attackers can leverage this account to access the administrative API over HTTP. The hardcoded account is named 'ServicesAPI' with the password 'b'. This allows for a pre-authentication remote code execution chain.
Recommendations
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 through 10.1.4 rev. 011974 PRE: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.2: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.3 through 10.3.3 rev. 011967 PRE: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.4 through 10.4.1 rev. 011941 PRE: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sitecore Experience Manager
Sitecore Experience Platform