Description
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Remediation
References
Related Vulnerabilities
Perl Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-1999-1386)
Apache Tomcat Other Vulnerability (CVE-2002-1895)
Jenkins Missing Authorization Vulnerability (CVE-2021-21687)
WebLogic CVE-2020-2967 Vulnerability (CVE-2020-2967)
Oracle Database Server CVE-2011-0870 Vulnerability (CVE-2011-0870)