What the vulnerability does
01Description
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.
Explanation of Vulnerability in Simple Terms
LiteSpeed Cache versions up to 6.5.0.1 contain a vulnerability that allows unauthenticated attackers to read, modify, or delete sensitive data on the site without requiring user interaction. The vulnerability stems from improper credential storage or transmission. All versions from 0 through 6.5.0.1 are affected. Site administrators should update immediately to a version newer than 6.5.0.1.
What an attacker can do
Read, modify, or delete sensitive site data without authentication.
Potential impact on your site
Attackers can compromise site data, user information, and site integrity without any credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities