Total vulnerabilities in the database
When using the zend-mail component to send email via the Zend\Mail\Transport\Sendmail transport
, a malicious user may be able to inject arbitrary parameters to the system sendmail program. The attack is performed by providing additional quote characters within an address; when unsanitized, they can be interpreted as additional command line arguments, leading to the vulnerability.
Software | From | Fixed in |
---|---|---|
![]() |
2.0.0 | 2.4.11 |