The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php5-phpmailerUpgrade php-phpmailer | Aug 30, 2017 | Dec 30, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 30, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 13, 2017 |
| Freebsd | — | Upgrade moodle32Upgrade moodle29Upgrade moodle31Upgrade phpmailerUpgrade moodle30Upgrade tt-rss | Mar 18, 2017 | Dec 28, 2016 |
| Moodle | — | Upgrade to the latest version of Moodle | Apr 19, 2017 | Dec 30, 2016 |
| Ubuntu | — | Upgrade libphp-phpmailer (Ubuntu Pro) | Mar 22, 2023 | Dec 30, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub