CVE-2023-29657: Malicious File Upload
Published May 12, 2023
·Updated
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
Affected Software
1 affected component
eXtplorer extplorer=2.1.15
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29657?
CVE-2023-29657 is categorized as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2023-29657?
To mitigate CVE-2023-29657, upgrade eXtplorer to version 2.1.16 or later where the vulnerability has been addressed.
3
What kind of attack can be executed via CVE-2023-29657?
CVE-2023-29657 allows attackers to upload malicious PHP files via insecure permissions, leading to arbitrary code execution on the server.
4
Which version of eXtplorer is affected by CVE-2023-29657?
CVE-2023-29657 specifically affects eXtplorer version 2.1.15.
5
Is CVE-2023-29657 being actively exploited?
While no specific exploits have been reported, the nature of CVE-2023-29657 suggests it could be a target for attackers due to its severity.