First published: Mon Jan 06 2020(Updated: )
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Litespeedtech Openlitespeed | <1.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5519 is classified as a medium severity vulnerability due to its potential to expose sensitive server configuration details.
To fix CVE-2020-5519, upgrade OpenLiteSpeed to version 1.6.5 or later.
CVE-2020-5519 affects OpenLiteSpeed versions prior to 1.6.5.
CVE-2020-5519 is a web application vulnerability that improperly checks request URLs.
CVE-2020-5519 could be exploited by attackers with a moderate skill level due to its weakness in request validation.