Vulnerability Description
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Interspire | Email Marketer | <= 6.1.6 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153018/Interspire-Email-Marketer-6.20-Remot
- https://medium.com/%40buiquang266/some-vulnerabilities-in-interspire-email-marke
- http://packetstormsecurity.com/files/153018/Interspire-Email-Marketer-6.20-Remot
- https://medium.com/%40buiquang266/some-vulnerabilities-in-interspire-email-marke
FAQ
What is CVE-2018-19550?
CVE-2018-19550 is a vulnerability with a CVSS score of 8.8 (HIGH). Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/te...
How severe is CVE-2018-19550?
CVE-2018-19550 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19550?
Check the references section above for vendor advisories and patch information. Affected products include: Interspire Email Marketer.