critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-5777 Scanner

CVE-2020-5777 scanner - Cross-Site Scripting (XSS) vulnerability in L-Soft LISTSERV

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
12
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-5777
9.8
CVSS

MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done by sending at least 151 simultaneous requests to the Magento website to trigger a "Too many connections" error, then use default magmi:magmi basic authentication to remotely bypass authentication.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
MAGMIby n/a
All versions prior to version 0.7.24
Updated Aug 21, 2026View on NVD →
Detail

L-Soft LISTSERV is an email list management software used for the creation and management of email newsletters, discussion groups, and email marketing campaigns. This software is primarily used by businesses, non-profit organizations, and educational institutions to communicate with their customers, members, and students. With L-Soft LISTSERV, users can manage large email lists, customize email content, and automate email delivery.

CVE-2020-5777 is a vulnerability that has been detected in L-Soft LISTSERV before 16.5-2018a. The vulnerability is caused by reflected cross-site scripting (XSS) which allows an attacker to inject malicious code into an unsecured web page. The vulnerability is found in the /scripts/wa.exe OK parameter and can allow an attacker to execute arbitrary JavaScript code on the victim's browser.

Exploiting this vulnerability can lead to a variety of malicious actions such as stealing the victim's login credentials, performing unauthorized transactions, and infecting the victim's computer with malware. The attacker can also use this vulnerability to redirect the victim to a malicious website or a phishing page that could result in further exploitation.

By leveraging the pro features of the s4e.io platform, users can identify vulnerabilities in their digital assets quickly and easily. With regular vulnerability scans and expert insights, s4e.io can help businesses and individuals protect themselves against known vulnerabilities like CVE-2020-5777 and stay one step ahead of malicious actors.

 

REFERENCES

Solution Advice

To protect against this vulnerability, L-Soft LISTSERV users can take the following precautions:

  • Install the latest security patches and updates for L-Soft LISTSERV
  • Enable content security policy (CSP) in the application to prevent cross-site scripting attacks
  • Conduct regular vulnerability scans and penetration testing to detect any security loopholes
  • Train employees on email security best practices, including identifying suspicious emails and avoiding clicking on links from unknown sources.
     

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-5777 scanner - Cross-Site Scripting (XSS) vulnerability in L-Soft LISTSERV S4E