Back

CRITICAL KEV

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property

Published Dec 30, 2016 ·Due Jul 28, 2025

Description

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 30, 2016
Updated Oct 21, 2025
Reserved Dec 22, 2016
CISA Vulnrichment
Updated Jul 17, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-5F37-GXVH-23V6