CVE-2025-34097 | ProcessMaker up to 3.5.3 Plugin install unrestricted upload (EDB-44399)
A vulnerability was found in ProcessMaker up to 3.5.3. It has been classified as critical. This affects the function install of the component Plugin Handler. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-34097. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.