Description
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Remediation
References
Related Vulnerabilities
WordPress Plugin File Manager Unspecified Vulnerability (4.1.4)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-19126)
MySQL CVE-2021-2048 Vulnerability (CVE-2021-2048)
Lighttpd Resource Management Errors Vulnerability (CVE-2010-0295)
WordPress Plugin BuddyPress Extended Friendship Request Cross-Site Scripting (1.0.1)