S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-15501 Scanner

CVE-2019-15501 scanner - Cross-Site Scripting (XSS) vulnerability in L-Soft LISTSERV

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-15501
6.1
CVSS

Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

L-Soft LISTSERV is a popular email list management software used by organizations and groups to send and manage email newsletters, discussion groups, and other email-based communications. It enables users to send newsletters to selected subscribers, manage lists of subscribers, and customize email templates as per their requirements. L-Soft LISTSERV also provides useful features such as archives, web-based subscription forms, and automated bounce handling. Morevoer, this program offers extensive logging that provides administrators with deep visibility into user activities.

The CVE-2019-15501 vulnerability is a critical security flaw discovered in L-Soft LISTSERV before version 16.5-2018a. This vulnerability arises in the OK parameter of the wa.exe script that allows for reflected cross-site scripting. It is important to note that cross-site scripting vulnerabilities are among the most common threats in web applications, and their impact is severe, which puts users' data at significant risk.

Exploiting this vulnerability can have disastrous consequences for users and organizations that use L-Soft LISTSERV. An attacker could send a malicious email to the LISTSERV mailing list which, when clicked by a subscriber, would execute the attacker’s code on the user's browser. This gives the attacker full control over the user's session and may allow them to conduct a variety of malicious activities, such as stealing sensitive information, installing malware on the device, or hijacking the account.

In conclusion, s4e.io provides the pro features and tools you need for robust vulnerability management, making it easy and quick for you to scan your system-threat landscape and identify possible security issues you might have missed. By implementing the precautions listed above and utilizing our platform's comprehensive security features, you can better protect your system from potential vulnerabilities and threats, mitigating the risk for your data or your organization.

 

REFERENCES

Solution Advice

To safeguard against such vulnerabilities, LISTSERV users must follow certain precautions, such as avoiding clicking on unknown email links, regularly updating their software, and running the latest version of their browser. The following is a bullet list of precautions that can be taken:

  • Upgrade to the latest LISTSERV version (16.5-2018a or higher) to patch the vulnerability.
  • Monitor the email list activity and respond promptly to any abnormal behavior.
  • Use security tools such as web application firewalls (WAFs) or intrusion detection systems (IDS) to identify and block any malicious traffic.
  • Keep the antivirus and anti-malware software updated.
  • Train users to recognize phishing emails or suspicious links and report these incidents immediately.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-15501 scanner - Cross-Site Scripting (XSS) vulnerability in L-Soft LISTSERV S4E