7.5
CVSSv3

CVE-2022-40319

Published: 17/01/2023 Updated: 25/01/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The LISTSERV 17 web interface allows remote malicious users to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lsoft listserv 17.0

Exploits

LISTSERV version 17 suffers from an insecure direct object reference vulnerability that allows illicit access to a target's profile ...