Interspire Email Marketer up to and including 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
interspire email marketer |