PHPMailer Bug Leaves Millions of Websites Open to Attack

General News

Summary

PHPMailer is a popular component used by an estimated 9 million sites for handing tasks such as email submission and registration forms. Golunski says the Sendemail validation is done using the RFC 3696 specification that in some circumstances allows hackers to add quotes and characters within an email address. When unverified, those quotes and characters can be interpreted as command line arguments that create the remote code execution vulnerability in PHPMailer. Golunski says a more complete description of the attack vectors and exploits will be disclosed at a later date, allowing more time for patching by impacted websites and platforms. ET to reflect the fact a bypass for the patch that fixed the PHPMailer bug has been found and that impacted parties will need to apply the upcoming software update once it becomes available.

Classifications

industries
HealthTech
applications
Web and Content Management

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

GitHub, Inc.
$1M to $5M