Lucene search

K
nvd[email protected]NVD:CVE-2022-40319
HistoryJan 17, 2023 - 9:15 p.m.

CVE-2022-40319

2023-01-1721:15:13
CWE-639
web.nvd.nist.gov
3
listserv
17
web interface
unauthorized modification
email address
idor
wa.exe url

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.007

Percentile

80.5%

The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim’s LISTSERV account.

Affected configurations

Nvd
Node
lsoftlistservMatch17.0
VendorProductVersionCPE
lsoftlistserv17.0cpe:2.3:a:lsoft:listserv:17.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.007

Percentile

80.5%

Related for NVD:CVE-2022-40319