CVE-2022-39195

MEDIUM NUCLEI

LISTSERV 17 - Cross-Site Scripting via c Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-39195. PoCs published by Shaunt Der-Grigorian. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in LISTSERV 17 via the 'c' parameter. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.

Description

A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.

Exploits (1)

exploitdb WORKING POC
by Shaunt Der-Grigorian · textwebappscgi
https://www.exploit-db.com/exploits/51148

This exploit demonstrates a reflected XSS vulnerability in LISTSERV 17 via the 'c' parameter. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: LISTSERV 17
No auth needed
Prerequisites: Access to the LISTSERV web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

LISTSERV 17 - Cross-Site Scripting
MEDIUMVERIFIEDby arafatansari
Shodan: http.html:"LISTSERV" || http.html:"listserv"
FOFA: body="listserv"

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0631
EPSS Percentile 92.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
lsoft/listserv 17.0
Published Jan 17, 2023
Tracked Since Feb 18, 2026