PT-2023-10638 · Unknown · Magnesium-Php

Published

2023-11-05

·

Updated

2024-08-05

·

CVE-2017-20187

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Magnesium-PHP versions up to 0.3.0
Description A vulnerability was found in Magnesium-PHP, classified as problematic. The issue affects the formatEmailString function of the file src/Magnesium/Message/Base.php. The manipulation of the email/name argument leads to injection. This vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For Magnesium-PHP versions up to 0.3.0, upgrade to version 0.3.1 to address this issue. As a temporary workaround, consider restricting the use of the formatEmailString function until the upgrade is applied.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2017-20187
GHSA-8PP6-5QPW-85G3

Affected Products

Magnesium-Php