Avoid installing XAMPP in the root directory or directories where non-admin users have write permissions.
The exploit takes advantage of a weakness in the XAMPP control panel, which allows an attacker to execute arbitrary code on the system. This can be done by sending a specially crafted request to the control panel, which then executes the malicious code.