vendor:
Litespeed Cache
by:
N/A
8.8
CVSS
HIGH
Stored Cross-site scripting (XSS)
79
CWE
Product Name: Litespeed Cache
Affected Version From: 3.6
Affected Version To: 3.6
Patch Exists: YES
Related CWE: N/A
CPE: a:litespeed_technologies:litespeed_cache
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64
2020
WordPress Plugin litespeed-cache 3.6 – ‘server_ip’ Cross-Site Scripting
A Stored Cross-site scripting (XSS) was discovered in wordpress plugins litespeed-cache 3.6. One parameters(server_ip) have Cross-Site Scripting.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.