PT-2017-3114 · Interspire · Interspire Email Marketer

Devcoinfet

·

Published

2017-09-12

·

Updated

2019-05-10

·

CVE-2017-14322

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Interspire Email Marketer (IEM) versions prior to 6.1.6
Description The issue is related to a weakness in the user registration check function in the init.php script of Interspire Email Marketer (IEM), which is associated with deficiencies in the authentication procedure. This can be exploited by a remote attacker to bypass the authentication procedure and gain administrative access by using a specially crafted IEM CookieLogin cookie.
Recommendations For versions prior to 6.1.6, update to version 6.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the IEM CookieLogin cookie to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02512
CVE-2017-14322

Affected Products

Interspire Email Marketer