First published: Tue Apr 16 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
LiteSpeed Cache | >=n/a<=5.7 | |
LiteSpeed Cache | <=5.7 |
Update to 5.7.0.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40000 is categorized as a Stored XSS vulnerability with significant risk to affected systems.
To fix CVE-2023-40000, update LiteSpeed Cache to version 5.8 or later, which addresses the XSS issues.
CVE-2023-40000 affects LiteSpeed Cache versions from n/a up to and including 5.7.
CVE-2023-40000 could allow attackers to execute scripts in the context of a user's browser, potentially compromising sensitive data.
Yes, the WordPress LiteSpeed Cache plugin up to version 5.7 is also vulnerable to CVE-2023-40000.