CVE-2023-54335: eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-54335?
CVE-2023-54335 is considered a critical vulnerability due to the potential for authentication bypass and remote code execution.
How do I fix CVE-2023-54335?
To fix CVE-2023-54335, upgrade eXtplorer to version 2.1.15 or later, which addresses the authentication bypass issue.
What are the risks associated with CVE-2023-54335?
The risks include unauthorized access to the system and the ability for attackers to upload and execute malicious code.
Who is affected by CVE-2023-54335?
All users of eXtplorer versions 2.1.14 and earlier are affected by CVE-2023-54335.
How can I mitigate the impact of CVE-2023-54335?
To mitigate the impact of CVE-2023-54335, implement network segmentation and restrict access to the eXtplorer interface until the patch is applied.