class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2421-1 | moodle security update |
EUVD |
EUVD-2022-7002 | class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header. |
Github GHSA |
GHSA-398j-f7m7-795j | PHPMailer vulnerable to email header injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T18:38:14.388Z
Reserved: 2012-01-19T00:00:00
Link: CVE-2012-0796
No data.
Status : Deferred
Published: 2012-07-17T10:20:53.053
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-0796
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA