S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-39195 Scanner

CVE-2022-39195 scanner - Cross-Site Scripting (XSS) vulnerability in LISTSERV

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-39195
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

LISTSERV is an email list management software that has been widely used by organizations for over three decades. Its primary purpose is to enable efficient communication between large groups of people via email. The software is used mainly in academic, research, and government institutions, where it facilitates the dissemination of information and communication among different departments and groups. The software has evolved over the years to accommodate new features such as web interface, thus making it more accessible for users.

The CVE-2022-39195 vulnerability is a cross-site scripting (XSS) vulnerability that affects the LISTSERV 17 web interface. This vulnerability allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter. As a result, the attackers can execute malicious code on the affected system and gain unauthorized access to sensitive data. This vulnerability can be exploited through a variety of attack vectors, including phishing emails and social engineering attacks.

If this vulnerability is exploited, attackers can gain access to confidential information such as user credentials, financial data, and proprietary information. This can lead to severe consequences, including loss of reputation, legal liabilities, and financial losses. Furthermore, it can lead to the compromise of other systems connected to the affected network.

Lastly, s4e.io offers an excellent platform for vulnerability scanning and identification of weaknesses in digital assets. Users can enjoy the benefits of the pro features by subscribing to the platform, where they get access to detailed reports, which provide critical insights on how to address identified vulnerabilities. Therefore, by staying ahead of vulnerabilities such as CVE-2022-39195, organizations can enhance their security posture and prevent potential data breaches.

 

REFERENCES

Solution Advice

The following measures can be taken to protect against this vulnerability:

  • Update the LISTSERV software to the latest version, which includes a fix for this vulnerability.
  • Implement security policies that prevent the execution of arbitrary code on the server-side.
  • Conduct regular security assessments to identify and address any vulnerabilities in the system.
  • Train users to identify and report suspicious emails and use two-factor authentication to enhance security.
  • Monitor network traffic and implement intrusion detection methods to detect any suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-39195 scanner - Cross-Site Scripting (XSS) vulnerability in LISTSERV | S4E