CVE-2023-54335 is a critical authentication bypass vulnerability affecting eXtplorer 2.1.14, allowing attackers to log in without a password by manipulating login requests. With a CVSS score of 9.8, this flaw is easily exploitable over the network with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Attackers can upload malicious PHP files and execute remote commands. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 94/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.1.14CPE match | cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:* | ||
<= 2.1.14CPE matchmatch criteria | cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
eXtplorer Authentication Bypass (CVE-2023-54335)
Mar 24, 2026eXtplorer Authentication Bypass (CVE-2023-54335)
Mar 24, 2026eXtplorer Authentication Bypass (CVE-2023-54335)
Mar 24, 2026