🔐 CVE Alert

CVE-2025-34097

UNKNOWN 0.0

ProcessMaker < 3.5.4 Authenticated Plugin Upload RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An attacker with administrative privileges can upload a malicious .tar plugin file containing arbitrary PHP code. Upon installation, the plugin’s install() method is invoked, resulting in execution of attacker-supplied PHP code on the server with the privileges of the web server user. This vulnerability can be chained with CVE-2022-38577 — a privilege escalation flaw in the user profile page — to achieve full remote code execution from a low-privileged account.

CWE CWE-434
Vendor processmaker inc.
Product processmaker
Published Jul 10, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for processmaker inc. processmaker

Be the first to know when new unknown vulnerabilities affecting processmaker inc. processmaker are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ProcessMaker Inc. / ProcessMaker
* < 3.5.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/processmaker_plugin_upload.rb wiki.processmaker.net: https://wiki.processmaker.net/3.0/Plugin_Development fortiguard.com: https://www.fortiguard.com/encyclopedia/ips/45757 exploit-db.com: https://www.exploit-db.com/exploits/44399 process-maker-authenticated-plugin-upload-rce: https://process-maker-authenticated-plugin-upload-rce vulncheck.com: https://vulncheck.com/advisories/process-maker-authenticated-plugin-upload-rce

Credits

bcoles