CVE-2022-40319 is an Insecure Direct Object Reference (IDOR) vulnerability in the LISTSERV 17 web interface, allowing remote attackers to modify a victim's LISTSERV account by manipulating email addresses in wa.exe URLs. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, leading to unauthorized data modification. While not currently on the CISA KEV catalog, public exploit code is available via ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.0CPE matchmatch criteria | cpe:2.3:a:lsoft:listserv:17.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.