CVE-2017-14322: Interspire Email Marketer

Critical severity, CVSS 9.8. EPSS: 36.5% chance of exploitation in the next 30 days.

The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.

Affected products

  • Interspire Email Marketer: up to and including 6.1.5

Published 2017-10-18. Last modified 2026-06-17.