Record summary

CVE-2024-47374 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template. VulnCheck reports CVE-2024-47374 use in known ransomware campaigns.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.0.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 19, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 7, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 6.5.0.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHLiteSpeed Cache <= 6.5.0.2 - Stored XSSCVSS 7.1

LiteSpeed Technologies LiteSpeed Cache versions up to 6.5.0.2 contain a stored cross-site scripting caused by improper input neutralization during web page generation, letting attackers execute malicious scripts in victim browsers, exploit requires storing malicious input.

Impact

Attackers can execute malicious scripts in victim browsers, leading to session hijacking, defacement, or redirection.

Remediation

Update to the latest version of LiteSpeed Cache.

WeaknessesCWE-79
AuthorsSourabh-Sahu
Template tagscvecve2024wordpresswp-pluginxssstoredlitespeedauthenticatedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CPE: cpe:2.3:a:litespeedtech:litespeed_cache:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/litespeed-cache/"
FOFA: body=/wp-content/plugins/litespeed-cache/
Google: inurl:"/wp-content/plugins/litespeed-cache/"

Source: ProjectDiscovery

References

3