Lucene search

K
osvGoogleOSV:GHSA-738M-F33V-QC2R
HistoryMar 05, 2020 - 10:09 p.m.

SMTP Injection in PHPMailer

2020-03-0522:09:19
Google
osv.dev
6

0.003 Low

EPSS

Percentile

65.6%

Impact

Attackers could inject arbitrary SMTP commands via by exploiting the fact that valid email addresses may contain line breaks, which are not handled correctly in some contexts.

Patches

Fixed in 5.2.14 in this commit.

Workarounds

Manually strip line breaks from email addresses before passing them to PHPMailer.

References

https://nvd.nist.gov/vuln/detail/CVE-2015-8476

For more information

If you have any questions or comments about this advisory: