Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade phpMailer to v5.2.27 due to Security issue #19

Open
TheFox opened this issue Mar 6, 2020 · 0 comments
Open

Upgrade phpMailer to v5.2.27 due to Security issue #19

TheFox opened this issue Mar 6, 2020 · 0 comments

Comments

@TheFox
Copy link
Owner

TheFox commented Mar 6, 2020

PHPMailer versions prior to 6.0.6 and 5.2.27 are vulnerable to an object injection attack by passing phar:// paths into addAttachment() and other functions that may receive unfiltered local paths, possibly leading to RCE.

See https://knasmueller.net/5-answers-about-php-phar-exploitation?cookie-state-change=1583482795465

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant