CVE-2016-10034
zend-mail remote code execution via Sendmail adapter
9.8
CRITICAL
CVSS 3.1
EPSS 38.4%
Description
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
How to fix CVE-2016-10034
To remediate CVE-2016-10034, upgrade the affected package to a fixed version below.
- —upgrade to 2.4.11 or later
Is CVE-2016-10034 being exploited?
Moderate — EPSS is 38.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.4.11
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |