CVE-2022-40319

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/01/2023
Last modified:
04/04/2025

Description

The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lsoft:listserv:17.0:*:*:*:*:*:*:*