Back

HIGH

Inclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailer

Published Jun 17, 2021

Description

PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace contains a function called php, it will be called in preference to the built-in validator of the same name. Mitigated in PHPMailer 6.5.0 by denying the use of simple strings as validator function names.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Jun 17, 2021
Updated Aug 3, 2024
Reserved Jun 15, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner @huntrdev
Published Jun 17, 2021
Updated Aug 3, 2024
Exploited since n/a
EUVD-2021-1277 GHSA-77MR-WC79-M8J3