← back
CVE-2022-40319highCWE-639

CVE-2022-40319

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.5epss 7.2%
from disclosure to weapon72 days
Published on NVDJan 17
1st PoC+72d
exploitation probability
7.2%top 6% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short

LISTSERV 17's web interface has a security flaw that allows attackers to modify other people's accounts by changing an email address in the web URL. This means someone could hijack your account without proper permission checks.

Technical detail

An IDOR vulnerability in LISTSERV 17's wa.exe endpoint fails to validate authorization when processing email address parameters in URLs, allowing attackers to modify arbitrary user accounts. The vulnerability requires network access to the web interface but no authentication, resulting in unauthorized account takeover and configuration changes.

Summary generated and translated by AI from the official description.
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.