Описание
ZendFramework potential remote code execution in zend-mail via Sendmail adapter
When using the zend-mail component to send email via the Zend\Mail\Transport\Sendmail transport, a malicious user may be able to inject arbitrary parameters to the system sendmail program. The attack is performed by providing additional quote characters within an address; when unsanitized, they can be interpreted as additional command line arguments, leading to the vulnerability.
Ссылки
Пакеты
Наименование
zendframework/zendframework
composer
Затронутые версииВерсия исправления
>= 2.0.0, < 2.4.11
2.4.11
6.5 Medium
CVSS3
Дефекты
CWE-74
6.5 Medium
CVSS3
Дефекты
CWE-74