Vulnerability Description
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lsoft | Listserv | 17.0 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/2301-exploits/listserv17-xss.txtThird Party AdvisoryVDB Entry
- https://peach.ease.lsoft.com/scripts/wa-PEACH.exe?A0=LSTSRV-LVendor Advisory
- https://packetstormsecurity.com/2301-exploits/listserv17-xss.txtThird Party AdvisoryVDB Entry
- https://peach.ease.lsoft.com/scripts/wa-PEACH.exe?A0=LSTSRV-LVendor Advisory
FAQ
What is CVE-2022-39195?
CVE-2022-39195 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
How severe is CVE-2022-39195?
CVE-2022-39195 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39195?
Check the references section above for vendor advisories and patch information. Affected products include: Lsoft Listserv.