Lucene search

K
nvd[email protected]NVD:CVE-2022-39195
HistoryJan 17, 2023 - 9:15 p.m.

CVE-2022-39195

2023-01-1721:15:13
CWE-79
web.nvd.nist.gov
2
cross-site scripting
listserv 17
web interface
remote attackers
javascript
html

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

66.0%

A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.

Affected configurations

Nvd
Node
lsoftlistservMatch17.0
VendorProductVersionCPE
lsoftlistserv17.0cpe:2.3:a:lsoft:listserv:17.0:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

66.0%