Record summary

CVE-2023-27641 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUML-Soft LISTSERV 16.5 - Cross-Site ScriptingCVSS 6.1

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

Impact

Successful exploitation could lead to unauthorized access or data theft.

Remediation

Update to the latest version of L-Soft LISTSERV to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscve2023cvexsslistservedblsoftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:lsoft:listserv:*:*:*:*:*:*:*:*
Shodan: http.html:"LISTSERV"
FOFA: body="listserv"

Source: ProjectDiscovery

References

2