The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
2016-12-30T19:59:00.137
2025-10-22T00:15:48.357
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | phpmailer_project | phpmailer | < 5.2.18 | Yes |
| Application | wordpress | wordpress | ≤ 4.7 | Yes |
| Application | joomla | joomla\! | ≤ 3.6.5 | Yes |