sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnerable to abuse, as the script allows anybody to specify arbitrary email recipients and include user-provided content in confirmation emails. This could enable malicious actors to use your server to send spam, phishing emails, or other malicious content, potentially damaging your domain's reputation and leading to blacklisting by email providers. Patched in version 1.0.0 by removing user-provided content from confirmation emails. All pre-release versions (alpha and beta) are vulnerable to this issue and should not be used. There are no workarounds for this issue. Users must upgrade to version 1.0.0 to mitigate the vulnerability.
History

Mon, 02 Dec 2024 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Spencer14420
Spencer14420 spemailhandler-php
CPEs cpe:2.3:a:spencer14420:spemailhandler-php:*:*:*:*:*:*:*:*
Vendors & Products Spencer14420
Spencer14420 spemailhandler-php
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Nov 2024 21:45:00 +0000

Type Values Removed Values Added
Description sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnerable to abuse, as the script allows anybody to specify arbitrary email recipients and include user-provided content in confirmation emails. This could enable malicious actors to use your server to send spam, phishing emails, or other malicious content, potentially damaging your domain's reputation and leading to blacklisting by email providers. Patched in version 1.0.0 by removing user-provided content from confirmation emails. All pre-release versions (alpha and beta) are vulnerable to this issue and should not be used. There are no workarounds for this issue. Users must upgrade to version 1.0.0 to mitigate the vulnerability.
Title Potential Abuse for Sending Arbitrary Emails in sp-php-email-handler
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-27T21:31:07.431Z

Updated: 2024-12-02T22:27:22.606Z

Reserved: 2024-11-22T17:30:02.144Z

Link: CVE-2024-53860

cve-icon Vulnrichment

Updated: 2024-12-02T22:27:16.077Z

cve-icon NVD

Status : Received

Published: 2024-11-27T22:15:05.833

Modified: 2024-11-27T22:15:05.833

Link: CVE-2024-53860

cve-icon Redhat

No data.