vendor:
Interspire Email Marketer
by:
Numan Türle
8.8
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: Interspire Email Marketer
Affected Version From: 6.20
Affected Version To: 6.20
Patch Exists: YES
Related CWE: CVE-2018-19550
CPE: a:interspire:interspire_email_marketer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Interspire Email Marketer 6.20 – Remote Code Execution
Interspire Email Marketer 6.20 is vulnerable to Remote Code Execution via upload files. An attacker can upload a malicious file to the server and execute arbitrary code. This vulnerability is due to insufficient validation of uploaded files in the surveys_submit.php file.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Interspire Email Marketer.