First published: Fri May 12 2023(Updated: )
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Explorer | =2.1.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29657 is categorized as a critical vulnerability due to the potential for arbitrary code execution.
To mitigate CVE-2023-29657, upgrade eXtplorer to version 2.1.16 or later where the vulnerability has been addressed.
CVE-2023-29657 allows attackers to upload malicious PHP files via insecure permissions, leading to arbitrary code execution on the server.
CVE-2023-29657 specifically affects eXtplorer version 2.1.15.
While no specific exploits have been reported, the nature of CVE-2023-29657 suggests it could be a target for attackers due to its severity.