CVE-2022-0072

EUVD-2022-15293
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
palo_altoCNA
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
litespeedtechopenlitespeed
1.6.5 ≤
𝑥
≤ 1.6.20.1
litespeedtechopenlitespeed
1.7.0 ≤
𝑥
< 1.7.16.1
litespeedtechopenlitespeed
1.5.11
litespeedtechopenlitespeed
1.5.12
𝑥
= Vulnerable software versions