peter bassill · operator
$ cve CVE-2023-54335 JSON

CVE-2023-54335

9.8
CRITICAL · CVSS 3.1 · EPSS 5.8% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.75% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2026-01-13
Last modified2026-10-06

Affected (1)

VendorProduct
extplorerextplorer

References

→ the Explorer  ·  watch your stack  ·  NVD