This high-severity vulnerability allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. It stems from a 'UNIX symlink following' weakness.
| Vendor | Product | Versions |
|---|---|---|
| litespeedtech | litespeed_cpanel_plugin | 2.3, 0, 2.4.4, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.5, 2.4.6, 2.4.7 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| litespeedtech | litespeed_whm_plugin | cve_cpe | 95% |
Updated description with technical details, changed severity to HIGH, added affected versions 2.4.5, 2.4.6, 2.4.7, and updated patch available to 2.4.8.
Updated severity to CRITICAL, CVSS score to 9.8, and added affected versions 2.4.0 to 2.4.4 along with a more detailed description.
Updated severity to CRITICAL, CVSS score to 9.8, added affected version 2.4.4, and included a more detailed description of the vulnerability.
Updated severity to CRITICAL, CVSS score to 10.0, and marked exploit as available.
Updated description with new technical details, changed severity to HIGH, marked as actively exploited, and noted that no exploit is available.
Initial creation