Skip to main content
CRITICAL

CVE-2023-54335

eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)

CVSS v3

9.8

CRITICAL

EPSS Score

5.8 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

Technical details

Published
2026-01-13
Last Modified
2026-02-03

Frequently asked questions

What is CVE-2023-54335?

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

Is CVE-2023-54335 actively exploited?

A proof-of-concept exploit exists for CVE-2023-54335, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2023-54335?

CVE-2023-54335 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-54335 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key