CVE-2022-0072

Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
litespeedtechopenlitespeed
1.6.5 ≤
𝑥
≤ 1.6.20.1
litespeedtechopenlitespeed
1.7.0 ≤
𝑥
< 1.7.16.1
litespeedtechopenlitespeed
1.5.11
litespeedtechopenlitespeed
1.5.12
𝑥
= Vulnerable software versions