Lucene search

K
freebsdFreeBSDC5D79773-8801-11E7-93F7-D43D7E971A1B
HistoryJul 27, 2017 - 12:00 a.m.

phpmailer -- XSS in code example and default exeception handler

2017-07-2700:00:00
vuxml.freebsd.org
25

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

40.6%

PHPMailer reports:

Fix XSS vulnerability in one of the code examples, CVE-2017-11503. The
code_generator.phps example did not filter user input prior to output. This
file is distributed with a .phps extension, so it it not normally executable
unless it is explicitly renamed, so it is safe by default. There was also an
undisclosed potential XSS vulnerability in the default exception handler
(unused by default). Patches for both issues kindly provided by Patrick
Monnerat of the Fedora Project.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchphpmailer< 5.2.24UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

40.6%