VulnerabilityModified
CVE-2022-44790
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.
HIGH 7.5EPSS 0.60%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- interspire/email marketer
- Source
- cve@mitre.org
References
- https://www.interspire.com/security-bulletin-2022-44790/Vendor Advisory
- https://www.interspire.com/security-bulletin-2022-44790/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.