Description
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Remediation
References
Related Vulnerabilities
DWR Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5325)
WordPress Plugin Backup by Supsystic Local File Inclusion (2.3.9)
Oracle Database Server SYS Account privilege issue (CVE-2021-2000)
WordPress Plugin WP Mobile Detector Unspecified Vulnerability (2.1)
WordPress Plugin AccessPress Social Icons Multiple Cross-Site Scripting Vulnerabilities (1.5.5)