PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libphp-phpmailer | Dec 8, 2018 | Nov 16, 2018 |
| Freebsd | — | Upgrade phpmailer6Upgrade phpmailer | Nov 22, 2018 | Nov 21, 2018 |
| Ubuntu | — | Upgrade libphp-phpmailer (Ubuntu Pro) | Mar 22, 2023 | Nov 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub