CVE-2020-5519: Input Validation
Published Jan 6, 2020
·Updated
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
Affected Software
1 affected component
Litespeedtech Openlitespeed<1.6.5
Event History
Jan 6, 2020
CVE Published
via MITRE·12:54 PM
Data Sourced
via MITRE·12:54 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-5519?
CVE-2020-5519 is classified as a medium severity vulnerability due to its potential to expose sensitive server configuration details.
2
How do I fix CVE-2020-5519?
To fix CVE-2020-5519, upgrade OpenLiteSpeed to version 1.6.5 or later.
3
What systems are affected by CVE-2020-5519?
CVE-2020-5519 affects OpenLiteSpeed versions prior to 1.6.5.
4
What kind of vulnerability is CVE-2020-5519?
CVE-2020-5519 is a web application vulnerability that improperly checks request URLs.
5
Is CVE-2020-5519 easy to exploit?
CVE-2020-5519 could be exploited by attackers with a moderate skill level due to its weakness in request validation.