vendor:
Openlitespeed WebServer
by:
cmOs - SunCSR
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Openlitespeed WebServer
Affected Version From: 1.7.2008
Affected Version To: 1.7.2008
Patch Exists: NO
Related CWE:
CPE: a:openlitespeed:openlitespeed_webserver:1.7.8
Platforms Tested: Windows 10
2021
Openlitespeed WebServer 1.7.8 – Command Injection (Authenticated)
The Openlitespeed WebServer version 1.7.8 is vulnerable to command injection. An attacker with authenticated access can inject a payload in the 'Command' value of the 'External App' configuration, leading to arbitrary command execution with the privileges of the web server. This can allow an attacker to take control of the affected system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Openlitespeed WebServer. Additionally, access to the dashboard should be restricted to trusted administrators only.