PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2021-04-27 20:15
Updated : 2021-06-14 08:17
NVD link : CVE-2020-36326
Mitre link : CVE-2020-36326
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
phpmailer_project
- phpmailer
wordpress
- wordpress