LISTSERV 17 web interface contains a cross-site scripting vulnerability. An attacker can inject arbitrary JavaScript or HTML via the "c" parameter, thereby possibly allowing the attacker to steal cookie-based authentication credentials and launch other attacks.
id: CVE-2022-39195
info:
name: LISTSERV 17 - Cross-Site Scripting
author: arafatansari
severi
...