2024-12-08 03:06:42 +00:00

88 lines
2.5 KiB
JSON

{
"id": "CVE-2022-44790",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-12-09T21:15:11.480",
"lastModified": "2024-11-21T07:28:27.517",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists."
},
{
"lang": "es",
"value": "Interspire Email Marketer hasta 6.5.1 permite la inyecci\u00f3n SQL a trav\u00e9s del m\u00f3dulo de encuestas. Un atacante no autenticado podr\u00eda realizar con \u00e9xito un ataque para extraer informaci\u00f3n potencialmente confidencial de la base de datos si la identificaci\u00f3n de la encuesta existe."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:interspire:email_marketer:*:*:*:*:*:*:*:*",
"versionEndIncluding": "6.5.1",
"matchCriteriaId": "135B9AD0-EBCB-4840-B0D7-184C2CE19D66"
}
]
}
]
}
],
"references": [
{
"url": "https://www.interspire.com/security-bulletin-2022-44790/",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.interspire.com/security-bulletin-2022-44790/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}