CVE-2025-34097 Details
Description
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An attacker with administrative privileges can upload a malicious .tar plugin file containing arbitrary PHP code. Upon installation, the plugin’s install() method is invoked, resulting in execution of attacker-supplied PHP code on the server with the privileges of the web server user. This vulnerability can be chained with CVE-2022-38577 — a privilege escalation flaw in the user profile page — to achieve full remote code execution from a low-privileged account.
A vulnerability allowing unrestricted file uploads has been identified in ProcessMaker versions prior to 3.5.4. This issue arises from improper handling of uploaded plugin archives, which enables an attacker with administrative privileges to upload a malicious .tar file containing arbitrary PHP code. Once the plugin is installed, the injected code is executed on the server with the privileges of the web server user. This vulnerability can be combined with a privilege escalation flaw in the user profile page to achieve full remote code execution from a low-privileged account.
Users are advised to update ProcessMaker to version 3.5.4 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2025CISA-ADP
Assessed Jul 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ProcessMaker | >= 1.6, <= 4276 >= 2.0.23, <= 2.0.23 (semver) >= 3.0-rc1, <= 3.0-rc1 >= 3.2.0, <= 3.2.0 (semver) >= 3.2.1, <= 3.2.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | New CVE Received | [email protected] |
Volerion