PT-2015-2870 · Php+1 · Phpmailer+1

Takeshi Terada

·

Published

2015-12-13

·

Updated

2020-03-05

·

CVE-2015-8476

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHPMailer versions prior to 5.2.14
Description The issue allows attackers to inject arbitrary SMTP commands via CRLF sequences in an email address to the validateAddress function in class.phpmailer.php or an SMTP command to the sendCommand function in class.smtp.php. This can be exploited by injecting line breaks into valid email addresses, which are not handled correctly in some contexts.
Recommendations For versions prior to 5.2.14, update to version 5.2.14 or later to resolve the issue. As a temporary workaround, consider manually stripping line breaks from email addresses before passing them to PHPMailer.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2512
BDU:2015-12236
CVE-2015-8476
DLA-363-1
DSA-3416-1
GHSA-738M-F33V-QC2R
MGASA-2015-0484

Affected Products

Alt Linux
Phpmailer