PT-2024-40077 · Unknown · Swiftmailer
Published
2024-05-29
·
Updated
2024-05-29
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
SwiftMailer versions prior to 5.2.1
Description:
The issue allows for arbitrary shell execution if the
From header comes from a non-trusted source and no Return-Path is configured. This can be exploited when using the sendmail transport, specifically the Swift Transport SendmailTransport.Recommendations:
For versions prior to 5.2.1, upgrade to version 5.2.1 or later as soon as possible to fix the issue. As a temporary workaround, consider configuring a
Return-Path to minimize the risk of exploitation when using the sendmail transport. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Swiftmailer