PT-2017-12058 · Php+2 · Phpmailer+2

Shahab Shamsi

·

Published

2017-07-20

·

Updated

2023-03-15

·

CVE-2017-11503

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPMailer version 5.2.23
Description The issue concerns a problem with the "From Email Address" and "To Email Address" fields in the code generator.php file, where there is XSS.
Recommendations For PHPMailer version 5.2.23, consider validating and sanitizing user input in the "From Email Address" and "To Email Address" fields to prevent XSS attacks. As a temporary workaround, restrict access to the code generator.php file until a fix is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2017-11503
GHSA-58MJ-PW57-4VM2
MGASA-2017-0257
USN-5956-1
USN-5956-2

Affected Products

Linuxmint
Phpmailer
Ubuntu