Command Injection Vulnerability in LiteSpeed Web Server Enterprise
CVE-2021-47903
Key Information:
- Vendor
Litespeed Technologies Inc
- Vendor
- CVE Published:
- 23 January 2026
Badges
What is CVE-2021-47903?
LiteSpeed Web Server Enterprise 5.4.11 is susceptible to an authenticated command injection flaw. This vulnerability allows authenticated administrators to execute arbitrary shell commands through the 'Command' parameter in the server's external app configuration interface. By exploiting this vulnerability, attackers can potentially perform remote code execution, leveraging path traversal techniques and bash command injection to compromise the server's integrity.
Affected Version(s)
LiteSpeed Web Server Enterprise 5.4.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
