LiteSpeed Cache <= 4.4.3 - Authorization Bypass

2021-11-30 00:00
Emil Kylander

Strategic Overview

Status
Patched in 4.4.4
Affected PluginLiteSpeed Cache
Affected Version1.0.15 – 4.4.3
CVSS6.5Medium
CVECVE-2021-24964
View all LiteSpeed Cache vulnerabilities

Vulnerability Overview

The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.

Technical Analysis

REMEDIATION: Update to version 4.4.4, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C