EXECUTIVE SUMMARY:
A critical vulnerability, CVE-2024-44000, has been discovered in the LiteSpeed Cache plugin for WordPress. This flaw allows unauthenticated users to potentially take over arbitrary accounts by exploiting a publicly exposed debug log file. The log file may contain sensitive information such as user cookies, enabling attackers to gain unauthorized access, including administrative privileges, on vulnerable sites. The issue arises if the debug feature is enabled, or if sites that had this feature activated have not removed the debug file. The vulnerability has been mitigated by relocating the log file to a more secure directory, randomizing filenames, and removing the logging of cookies. It is advised to check for the presence of the debug log file, remove it if found, and implement .htaccess rules to deny direct access to log files.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical vulnerability, CVE-2024-44000, has been discovered in the LiteSpeed Cache plugin for WordPress. This flaw allows unauthenticated users to potentially take over arbitrary accounts by exploiting a publicly exposed debug log file. The log file may contain sensitive information such as user cookies, enabling attackers to gain unauthorized access, including administrative privileges, on vulnerable sites. The issue arises if the debug feature is enabled, or if sites that had this feature activated have not removed the debug file. The vulnerability has been mitigated by relocating the log file to a more secure directory, randomizing filenames, and removing the logging of cookies. It is advised to check for the presence of the debug log file, remove it if found, and implement .htaccess rules to deny direct access to log files.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/09/critical-security-flaw-found-in.html