CRITICAL🇵🇱 Wersja polska

CVE-2023-54335

CVSS 9.3v4.0pub. 2026-01-13upd. 2026-02-03

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

🤖 AI Analysis
How it works

The vulnerability results from insufficient user identity verification during the login process (CWE-306 — missing authentication for critical function). An attacker can manipulate a login request in such a way as to bypass the password verification mechanism and gain access to the file management panel without knowing any authentication credentials. After gaining access, it is possible to upload a malicious PHP file to the system and then execute it remotely, resulting in full RCE on the server.

Impact

An attacker gains unauthorized access to the file management system and can subsequently take full control of the server by executing arbitrary system commands (RCE). The vulnerability allows complete server takeover, data theft, file modification, and potential use of the system as a launching point for further attacks.

Mitigation & patch

Apply patches available from the vendor according to the references. It is recommended to restrict access to the eXtplorer interface exclusively to trusted IP addresses using a firewall or web server rules until updates are applied. If no patch is available, consider disabling or removing the application from the production environment.

Who is affected

eXtplorer version 2.1.14

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Extplorer

    APP
    Extplorer
    ≤ 2.1.14
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2012-6710CRITICAL9.8PL ✓same product

eXtplorer — pominięcie uwierzytelnienia przez pustą tablicę hasła

CVE-2023-29657HIGH8.8same product

eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file ...

CVE-2023-27842HIGH8.8same product

Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker...

CVE-2017-12756HIGH7.2same product

Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command ...

CVE-2016-4313HIGH7.8same product

Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execu...