Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6265
HistoryMay 10, 2018 - 3:25 a.m.

Arbitrary Code Execution

2018-05-1003:25:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.944 High

EPSS

Percentile

99.2%

swiftmailer/swiftmailer is vulnerable to arbitrary code execution. The malicious code can be passed through the extraParams variable used to send extra parameters if the From, ReturnPath or Sender header came from a non-trusted source.

CPENameOperatorVersion
swiftmailer/swiftmailerle5.4.4