CVE-2017-14322 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 36.5% (pctl 98)
Patch early
A public exploit exists.
Description
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 36.51% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-10-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| interspire | email marketer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass | 2018-04-24 |
References
- http://seclists.org/fulldisclosure/2017/Oct/39
- https://security.infoteam.ch/en/blog/posts/narrative-of-an-incident-response-from-compromise-to-the-publication-of-the-weakness.html
- https://www.exploit-db.com/exploits/44513/
- http://seclists.org/fulldisclosure/2017/Oct/39
- https://security.infoteam.ch/en/blog/posts/narrative-of-an-incident-response-from-compromise-to-the-publication-of-the-weakness.html
- https://www.exploit-db.com/exploits/44513/
→ the Explorer · watch your stack · NVD