Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.interspire.com/security-bulletin-2022-44790/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-12-09T00:00:00
Updated: 2024-08-03T14:01:31.316Z
Reserved: 2022-11-07T00:00:00
Link: CVE-2022-44790
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-09T21:15:11.480
Modified: 2024-11-21T07:28:27.517
Link: CVE-2022-44790
Redhat
No data.