Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.interspire.com/security-bulletin-2022-44790/ |
|
History
Wed, 23 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2022-12-09T00:00:00.000Z
Updated: 2025-04-23T14:15:14.721Z
Reserved: 2022-11-07T00:00:00.000Z
Link: CVE-2022-44790
Updated: 2024-08-03T14:01:31.316Z
Status : Modified
Published: 2022-12-09T21:15:11.480
Modified: 2025-04-23T15:15:53.120
Link: CVE-2022-44790
No data.