PT-2024-40077 · Unknown · Swiftmailer

Published

2024-05-29

·

Updated

2024-05-29

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: SwiftMailer versions prior to 5.2.1
Description: The issue allows for arbitrary shell execution if the From header comes from a non-trusted source and no Return-Path is configured. This can be exploited when using the sendmail transport, specifically the Swift Transport SendmailTransport.
Recommendations: For versions prior to 5.2.1, upgrade to version 5.2.1 or later as soon as possible to fix the issue. As a temporary workaround, consider configuring a Return-Path to minimize the risk of exploitation when using the sendmail transport.

Related Identifiers

GHSA-4QPJ-GXXG-JQG4

Affected Products

Swiftmailer