Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gff2-p6vm-3p8g

Опубликовано: 07 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

ZendFramework potential remote code execution in zend-mail via Sendmail adapter

When using the zend-mail component to send email via the Zend\Mail\Transport\Sendmail transport, a malicious user may be able to inject arbitrary parameters to the system sendmail program. The attack is performed by providing additional quote characters within an address; when unsanitized, they can be interpreted as additional command line arguments, leading to the vulnerability.

Пакеты

Наименование

zendframework/zendframework

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.4.11

2.4.11

6.5 Medium

CVSS3

Дефекты

CWE-74

6.5 Medium

CVSS3

Дефекты

CWE-74