GHSA-77mr-wc79-m8j3

    Dashboard / Vulnerabilities / GHSA-77mr-wc79-m8j3

    GHSA-77mr-wc79-m8j3

    Published: 22 Jun 2021Last Modified: 17 Feb 2024

    Summary: PHPMailer untrusted code may be run from an overridden address validator

    Details: If a function is defined that has the same name as the default built-in email address validation scheme (`php`), it will be called in default configuration as when no validation scheme is provided, the default scheme's callable `php` was being called. If an attacker is able to inject such a function into the application (a much bigger issue), it will be called whenever an email address is validated, such as when calling `validateAddress()`. ### Impact Low impact – exploitation requires that an attacker can already inject code into an application, but it provides a trigger pathway. ### Patches This is patched in PHPMailer 6.5.0 by denying the use of simple strings as validator function names, which is a very minor BC break. ### Workarounds Inject your own email validator function. ### References Reported by [Vikrant Singh Chauhan](mailto:[email protected]) via [huntr.dev](https://www.huntr.dev/). [CVE-2021-3603](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3603) ### For more information If you have any questions or comments about this advisory: * Open an issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer) * [Email us](mailto:[email protected]).

    Affected packages

    Package

    Name: phpmailer/phpmailer

    Purl: pkg:composer/phpmailer/phpmailer

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -6.5.0

    Affected versions

    v5.2.10
    v5.2.11
    v5.2.12
    v5.2.13
    v5.2.14
    v5.2.15
    v5.2.16
    v5.2.17
    v5.2.18
    v5.2.19
    v5.2.2
    v5.2.20
    v5.2.21
    v5.2.22
    v5.2.23
    v5.2.24
    v5.2.25
    v5.2.26
    v5.2.27
    v5.2.28
    v5.2.4
    v5.2.5
    v5.2.6
    v5.2.7
    v5.2.8
    v5.2.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-77mr-wc79-m8j3 | CVE-DB