github.com
https://github.com/hosakauk/exploits/blob/master/listserv_report_xss.MD CVE-2023-27641
MEDIUMNuclei
L-Soft LISTSERV 16.5 - Cross-Site Scripting
Record summary
CVE-2023-27641 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUML-Soft LISTSERV 16.5 - Cross-Site ScriptingCVSS 6.1
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.
Impact
Successful exploitation could lead to unauthorized access or data theft.
Remediation
Update to the latest version of L-Soft LISTSERV to mitigate the XSS vulnerability.
WeaknessesCWE-79
Authorsritikchaddha
Template tagscve2023cvexsslistservedblsoftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:lsoft:listserv:*:*:*:*:*:*:*:*
Shodan: http.html:"LISTSERV"
FOFA: body="listserv"
https://github.com/hosakauk/exploits/blob/master/listserv_report_xss.MD https://nvd.nist.gov/vuln/detail/CVE-2023-27641
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-27641