LiteSpeed web server is "an Apache interchangeable, full-featured high performance, secure HTTP server specifically engineered from the ground up with security and scalability in mind". A cross site scripting vulnerability in LiteSpeed allows attackers to cause the program to insert arbitrary HTML and/or JavaScript into responses it sends back to the user.
Credit:
The information has been provided by Gama Sec.
When configuring the server the "confMgr.php" script doesn't properly validate user-supplied input in the 'm' parameter, this allows attackers to cause a cross site scripting attack.