Lucene search

K
osvGoogleOSV:GHSA-PR44-4JFR-286M
HistoryMay 17, 2022 - 12:27 a.m.

Swift Mailer mail transport Command Injection

2022-05-1700:27:49
Google
osv.dev
5

7.7 High

AI Score

Confidence

Low

0.944 High

EPSS

Percentile

99.2%

The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.