PT-2015-2870 · Php+1 · Phpmailer+1
Takeshi Terada
·
Published
2015-12-13
·
Updated
2020-03-05
·
CVE-2015-8476
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHPMailer versions prior to 5.2.14
Description
The issue allows attackers to inject arbitrary SMTP commands via CRLF sequences in an email address to the
validateAddress function in class.phpmailer.php or an SMTP command to the sendCommand function in class.smtp.php. This can be exploited by injecting line breaks into valid email addresses, which are not handled correctly in some contexts.Recommendations
For versions prior to 5.2.14, update to version 5.2.14 or later to resolve the issue.
As a temporary workaround, consider manually stripping line breaks from email addresses before passing them to PHPMailer.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Phpmailer