← back
CVE-2021-47903

LiteSpeed Web Server Enterprise 5.4.11 - Command Injection

CVSS 8.6 HIGHEPSS 1.4%CWE-78
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N