eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
The vulnerability results from insufficient user identity verification during the login process (CWE-306 — missing authentication for critical function). An attacker can manipulate a login request in such a way as to bypass the password verification mechanism and gain access to the file management panel without knowing any authentication credentials. After gaining access, it is possible to upload a malicious PHP file to the system and then execute it remotely, resulting in full RCE on the server.
An attacker gains unauthorized access to the file management system and can subsequently take full control of the server by executing arbitrary system commands (RCE). The vulnerability allows complete server takeover, data theft, file modification, and potential use of the system as a launching point for further attacks.
Apply patches available from the vendor according to the references. It is recommended to restrict access to the eXtplorer interface exclusively to trusted IP addresses using a firewall or web server rules until updates are applied. If no patch is available, consider disabling or removing the application from the production environment.
eXtplorer version 2.1.14
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExtplorer
APPExtplorer≤ 2.1.14
Related vulnerabilities
eXtplorer — pominięcie uwierzytelnienia przez pustą tablicę hasła
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file ...
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker...
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command ...
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execu...