Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4698
HistoryJul 26, 2017 - 8:32 a.m.

Multiple CRLF Injection

2017-07-2608:32:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.003 Low

EPSS

Percentile

65.8%

PHPMailer is vulnerable to multiple CRLF injection attacks. The attacks exist because it does not filter address inputs with line breaks. A malicious user can pass an email address to the validateAddress function in class.phpmailer.php or pass SMTP commands to the sendCommand function in class.smtp.php, leading to a message injection attack.

CPENameOperatorVersion
phpmailer/phpmailerle5.2.13