Описание
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
Ссылки
- Permissions RequiredThird Party Advisory
- Vendor Advisory
- Permissions RequiredThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.5 (исключая)
cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00518
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
больше 3 лет назад
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
EPSS
Процентиль: 66%
0.00518
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-20