PT-2017-3114 · Interspire · Interspire Email Marketer
Devcoinfet
·
Publicado
2017-09-12
·
Atualizado
2019-05-10
·
CVE-2017-14322
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Interspire Email Marketer (IEM) versions prior to 6.1.6
Description
The issue is related to a weakness in the user registration check function in the init.php script of Interspire Email Marketer (IEM), which is associated with deficiencies in the authentication procedure. This can be exploited by a remote attacker to bypass the authentication procedure and gain administrative access by using a specially crafted IEM CookieLogin cookie.
Recommendations
For versions prior to 6.1.6, update to version 6.1.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
IEM CookieLogin cookie to minimize the risk of exploitation.Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Interspire Email Marketer