PT-2017-3114 · Interspire · Interspire Email Marketer

Devcoinfet

·

Publicado

2017-09-12

·

Atualizado

2019-05-10

·

CVE-2017-14322

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Interspire Email Marketer (IEM) versions prior to 6.1.6
Description The issue is related to a weakness in the user registration check function in the init.php script of Interspire Email Marketer (IEM), which is associated with deficiencies in the authentication procedure. This can be exploited by a remote attacker to bypass the authentication procedure and gain administrative access by using a specially crafted IEM CookieLogin cookie.
Recommendations For versions prior to 6.1.6, update to version 6.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the IEM CookieLogin cookie to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02512
CVE-2017-14322

Produtos afetados

Interspire Email Marketer