Vulnerability Description
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lsoft | Listserv | 17.0 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/2301-exploits/listserv17-idor.txtThird Party AdvisoryVDB Entry
- https://peach.ease.lsoft.com/scripts/wa-PEACH.exe?A0=LSTSRV-LVendor Advisory
- https://packetstormsecurity.com/2301-exploits/listserv17-idor.txtThird Party AdvisoryVDB Entry
- https://peach.ease.lsoft.com/scripts/wa-PEACH.exe?A0=LSTSRV-LVendor Advisory
FAQ
What is CVE-2022-40319?
CVE-2022-40319 is a vulnerability with a CVSS score of 7.5 (HIGH). The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification ...
How severe is CVE-2022-40319?
CVE-2022-40319 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40319?
Check the references section above for vendor advisories and patch information. Affected products include: Lsoft Listserv.