PT-2022-25535 · Interspire · Interspire Email Marketer

Le Nguyen

+1

·

Published

2022-10-11

·

Updated

2022-10-13

·

CVE-2022-40777

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Interspire Email Marketer versions prior to 6.5.1
Description The issue allows for arbitrary file upload through a "create survey and submit survey" operation in surveys submit.php. This can lead to a .php file being accessible under the /admin/temp/surveys/ URI, potentially causing security issues. The problem exists due to an incomplete fix for a previous issue.
Recommendations For versions prior to 6.5.1, update to version 6.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the surveys submit.php file to minimize the risk of exploitation. Avoid using the "create survey and submit survey" operation in surveys submit.php until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-40777

Affected Products

Interspire Email Marketer