What the vulnerability does
01Description
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
Explanation of Vulnerability in Simple Terms
LiteSpeed Cache versions up to 6.4.1 contain a path traversal vulnerability that allows authenticated users with low privileges to read, modify, or delete files on the server. An attacker can exploit this by crafting malicious requests to access files outside the intended directory. This affects confidentiality, integrity, and availability of the site.
What an attacker can do
Read, modify, or delete files on the server outside the cache directory.
Potential impact on your site
Any authenticated user can access sensitive files, alter site configuration, or cause service disruption.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities