CVE-2025-34509
BaseFortify
Publication date: 2025-06-17
Last updated on: 2025-09-08
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sitecore | experience_commerce | From 9.0 (inc) to 10.4 (inc) |
| sitecore | experience_manager | From 9.0 (inc) to 10.4 (inc) |
| sitecore | experience_platform | From 9.0 (inc) to 10.4 (exc) |
| sitecore | experience_platform | 10.4 |
| sitecore | managed_cloud | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.4.1 rev. 011941 PRE, where a hardcoded user account is present. Unauthenticated and remote attackers can exploit this hardcoded account to gain access to the administrative API over HTTP.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain unauthorized administrative access remotely without authentication. This can lead to high confidentiality impact, partial integrity compromise, and potentially unauthorized control over the system's administrative functions.