Cross-Site Scripting Vulnerability in LiteSpeed Web Server
CVE-2012-4871

Currently unrated

Key Information:

Vendor
CVE Published:
6 September 2012

What is CVE-2012-4871?

A cross-site scripting (XSS) vulnerability in the administrator panel of LiteSpeed Web Server versions prior to 4.1.11 allows remote attackers to inject arbitrary web scripts or HTML via the 'gtitle' parameter in the service/graph_html.php file. This can lead to unauthorized access to sensitive data or actions performed on behalf of the authenticated users. Administrators are advised to update to the latest version and validate input to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.