CVE-2021-47903

HIGH

LiteSpeed Web Server Enterprise 5.4.11 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47903. PoCs published by SunCSR.

AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in LiteSpeed Web Server Enterprise 5.4.11. It leverages authenticated access to inject a reverse shell payload via the 'Command' field in the External App configuration, leading to remote code execution.

Description

LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.

Exploits (1)

exploitdb WORKING POC
by SunCSR · textwebappsphp
https://www.exploit-db.com/exploits/49523

This exploit demonstrates a command injection vulnerability in LiteSpeed Web Server Enterprise 5.4.11. It leverages authenticated access to inject a reverse shell payload via the 'Command' field in the External App configuration, leading to remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: LiteSpeed Web Server Enterprise 5.4.11
Auth required
Prerequisites: Authenticated access to the LiteSpeed Web Server dashboard · Administrator privileges · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/49523
Various Sources product
https://www.litespeedtech.com/
Various Sources product
https://www.litespeedtech.com/products

Scores

CVSS v3 8.8
EPSS 0.0145
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Published Jan 23, 2026
Tracked Since Feb 18, 2026