CVE-2021-47855
HIGHOpenlitespeed 1.7.9 - XSS
Title source: llmDescription
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
Exploits (1)
Scores
CVSS v3
7.2
EPSS
0.0004
EPSS Percentile
12.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
LiteSpeed Technologies/OpenLiteSpeed
1.7.9
Published
Jan 21, 2026
Tracked Since
Feb 18, 2026