Skip to content

2007-06-14 Shell command injection

High
Synchro published GHSA-6h78-85v2-mmch Mar 5, 2020

Package

composer PHPMailer (Composer)

Affected versions

< 1.7.4

Patched versions

1.7.4

Description

Impact

Shell command injection, remotely exploitable if host application does not filter user data appropriately.

Patches

Fixed in 1.7.4

Workarounds

Filter and validate user-supplied data before putting in the into the Sender property.

References

https://nvd.nist.gov/vuln/detail/CVE-2007-3215

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2007-3215

Weaknesses

No CWEs