Arbitrary Email Header Injection in PHPMailer Library

Arbitrary Email Header Injection in PHPMailer Library

CVE-2012-0796 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

Learn more about our User Device Pen Test.