CVE-2021-47903

HIGH

LiteSpeed Web Server Enterprise 5.4.11 - Command Injection

Title source: llm

Description

LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.

Exploits (1)

exploitdb WORKING POC
by SunCSR · textwebappsphp
https://www.exploit-db.com/exploits/49523

Scores

CVSS v3 8.8
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Published Jan 23, 2026
Tracked Since Feb 18, 2026