LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-23 17:16
Updated : 2026-01-26 15:03
NVD link : CVE-2021-47903
Mitre link : CVE-2021-47903
CVE.ORG link : CVE-2021-47903
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
