Description
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
cmOs
References
www.exploit-db.com/exploits/49727 (ExploitDB-49727)
openlitespeed.org/ (OpenLiteSpeed Vendor Homepage)
www.vulncheck.com/...speed-notes-stored-cross-site-scripting (VulnCheck Advisory: Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting)