Interspire Email Marketer version 6.0.0 to 6.5.0 that have the Surveys addon enabled allows arbitrary file upload via surveys_submit.php “create survey and submit survey” operation, which can cause a .php file to be accessible under a /admin/temp/surveys/
URI.
We recommend that all users of Email Marketer immediately take one of the following corrective actions.
If you are not using the survey functionality of Email Marketer:
- Disable the survey add on from the addon management screen:
- Backup and delete the file
~/surveys_submit.php
Or
If you are using the survey functionality of Email Marketer:
- Download the updated version surveys_submit.php
- Backup and delete the file
~/surveys_submit.php
- Unzip the updated version of surveys_submit.php in your installation directory
Or
Update to the latest version of Email Marketer:
If you have an active download link, get and update to the latest version of Email Marketer which at the time of this writing is version 6.5.1.
The CVE number is CVE-2022-40777. Discovered by Nguyen Huy Vinh, Le Nguyen of Viettel Cyber Security