VYPR
Unrated severityNVD Advisory· Published Oct 11, 2022· Updated Aug 3, 2024

CVE-2022-40777

CVE-2022-40777

Description

Interspire Email Marketer 6.0.0–6.5.0 with Surveys addon allows arbitrary PHP file upload via surveys_submit.php, leading to remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Interspire Email Marketer 6.0.0–6.5.0 with Surveys addon allows arbitrary PHP file upload via surveys_submit.php, leading to remote code execution.

Vulnerability

Interspire Email Marketer versions 6.0.0 through 6.5.0 with the Surveys addon enabled are vulnerable to arbitrary file upload. The surveys_submit.php script, used in the "create survey and submit survey" operation, does not properly validate uploaded files, allowing a .php file to be placed under the /admin/temp/surveys/ directory. This issue is an incomplete fix for CVE-2018-19550 [1].

Exploitation

An attacker must have network access to the application and the Surveys addon must be enabled. No authentication is required to reach the vulnerable endpoint. The attacker can craft a malicious .php file and submit it via the survey submission functionality. The file is then stored in the /admin/temp/surveys/ directory and can be accessed directly via a web request, leading to code execution [1].

Impact

Successful exploitation allows an unauthenticated attacker to upload and execute arbitrary PHP code on the server. This can lead to full compromise of the web application and underlying server, including data theft, defacement, or further lateral movement [1].

Mitigation

Interspire has released version 6.5.1 which fixes the vulnerability. Users are advised to update to the latest version. If updating is not immediately possible, users who do not use the survey functionality should disable the Surveys addon and delete the surveys_submit.php file. Users who rely on surveys can download an updated version of surveys_submit.php from the vendor's security bulletin [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.