LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
History

Fri, 23 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
Description LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
Title LiteSpeed Web Server Enterprise 5.4.11 - Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-23T16:47:42.757Z

Updated: 2026-01-23T16:47:42.757Z

Reserved: 2026-01-18T12:35:05.176Z

Link: CVE-2021-47903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-23T17:16:02.743

Modified: 2026-01-23T17:16:02.743

Link: CVE-2021-47903

cve-icon Redhat

No data.