Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting
Vulnerability Description
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47855
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- cmOs
References
More from LiteSpeed Technologies
View All →Affected Vendor
LiteSpeed Technologies
View all reports →