PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpmailer | Phpmailer_project | * | 5.2.27 (excluding) |
Phpmailer | Phpmailer_project | 6.0.0 (including) | 6.0.6 (excluding) |
Libphp-phpmailer | Ubuntu | bionic | * |
Libphp-phpmailer | Ubuntu | cosmic | * |
Libphp-phpmailer | Ubuntu | esm-apps/bionic | * |
Libphp-phpmailer | Ubuntu | esm-apps/xenial | * |
Libphp-phpmailer | Ubuntu | trusty | * |
Libphp-phpmailer | Ubuntu | upstream | * |
Libphp-phpmailer | Ubuntu | xenial | * |