← volver
CVE-2021-47903highCWE-78

LiteSpeed Web Server Enterprise 5.4.11 - Command Injection

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.6epss 1.6%
probabilidad de explotación
1.6%top 25% de las CVE
explotación observada
noninguna fuente lo reporta
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N