CVE-2021-47855
EUVD-2026-363221.01.2026, 18:16
Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon.
Awaiting analysis
This vulnerability is currently awaiting analysis.