HIGH
Inclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailer
Published Jun 17, 2021
8.1
HIGHCVSS 3.1
EPSS 2.26%
Description
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace contains a function called php, it will be called in preference to the built-in validator of the same name. Mitigated in PHPMailer 6.5.0 by denying the use of simple strings as validator function names.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<6.5.0
- Version
Configuration 1
- ≤ 6.4.1
Configuration 2
OR
- 33
- 34
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1277 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/phpmailer/phpmailer/CVE-2021-3603.yaml
- https://github.com/PHPMailer/PHPMailer/commit/45f3c18dc6a2de1cb1bf49b9b249a9ee36a5f7f3 x_refsource_MISCPatchThird Party Advisory
- https://github.com/PHPMailer/PHPMailer/releases/tag/v6.5.0
- https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-77mr-wc79-m8j3
- https://github.com/advisories/GHSA-77mr-wc79-m8j3 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YRMWGA4VTMXFB22KICMB7YMFZNFV3EJ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FJYSOFCUBS67J3TKR74SD3C454N7VTYM/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2021-3603
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3603
- https://www.huntr.dev/bounties/1-PHPMailer/PHPMailer/ x_refsource_CONFIRMProduct
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Jun 17, 2021
Updated Aug 3, 2024
Reserved Jun 15, 2021
Link CVE-2021-3603
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-1277 GHSA-77MR-WC79-M8J3 Assigner @huntrdev
Published Jun 17, 2021
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-1277