vendor:
Email Marketer
by:
devcoinfet
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Email Marketer
Affected Version From: 6.1.3
Affected Version To: 6.1.6
Patch Exists: YES
Related CWE: CVE-2017-14322
CPE: a:interspire:email_marketer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Below 6.1.6
2018
Interspire Email Marketer – Remote Admin Authentication Bypass
Interspire Email Marketer versions 6.1.3-6.1.6 are vulnerable to an authentication bypass vulnerability. An attacker can exploit this vulnerability by sending a specially crafted request to the application with a forged cookie. This will allow the attacker to gain access to the application without authentication.
Mitigation:
Upgrade to the latest version of Interspire Email Marketer and ensure that all security patches are applied.