The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php-phpmailerUpgrade php5-phpmailer | Aug 30, 2017 | Dec 30, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 30, 2016 |
| Debian | — | Upgrade libphp-phpmailer | Jan 1, 2017 | Dec 30, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 24, 2017 |
| Freebsd | — | Upgrade phpmailerUpgrade tt-rss | Dec 27, 2016 | Dec 26, 2016 |
| Ubuntu | — | Upgrade libphp-phpmailer (Ubuntu Pro) | Mar 22, 2023 | Dec 30, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub