Vulnerabilities > CVE-2022-40319 - Authorization Bypass Through User-Controlled Key vulnerability in Lsoft Listserv 17.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |