CVE-2021-47855
HIGHOpenLiteSpeed 1.7.9 - Stored Cross-Site Scripting in Dashboard Notes Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47855. PoCs published by cmOs.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Openlitespeed 1.7.9 by injecting a malicious script into the 'Notes' parameter, which executes when an administrator views the Default Icon.
Description
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Openlitespeed 1.7.9 by injecting a malicious script into the 'Notes' parameter, which executes when an administrator views the Default Icon.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N