Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nguyen Huy Vinh

Researcher fromViettel Cyber Security
#30061of 53,633
8.8Total CVSS
Vulnerabilities · 1
PT-2022-25535
8.8
2022-10-11
Interspire · Interspire Email Marketer · CVE-2022-40777
**Name of the Vulnerable Software and Affected Versions** Interspire Email Marketer versions prior to 6.5.1 **Description** The issue allows for arbitrary file upload through a "create survey and submit survey" operation in surveys submit.php. This can lead to a .php file being accessible under the /admin/temp/surveys/ URI, potentially causing security issues. The problem exists due to an incomplete fix for a previous issue. **Recommendations** For versions prior to 6.5.1, update to version 6.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the surveys submit.php file to minimize the risk of exploitation. Avoid using the "create survey and submit survey" operation in surveys submit.php until the issue is resolved.