Insecure Permissions in eXtplorer 2.1.15 Allows Arbitrary Code Execution
CVE-2023-29657
8.8HIGH
What is CVE-2023-29657?
eXtplorer version 2.1.15 is compromised by a vulnerability that allows attackers to exploit insecure permissions in its file management capabilities. This weakness permits unauthorized file uploads of ZIP files containing PHP scripts, potentially leading to arbitrary code execution on the server. By leveraging this flaw, malicious users may gain access to sensitive data, disrupt services, or further exploit the system for additional attacks.
