CVE-2017-15806
Zeta Components Mail Arbitrary code execution via a crafted email address
8.1
HIGH
CVSS 3.1
EPSS 10.7%
Description
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."
How to fix CVE-2017-15806
To remediate CVE-2017-15806, upgrade the affected package to a fixed version below.
- —upgrade to 1.8.2 or later
Is CVE-2017-15806 being exploited?
Moderate — EPSS is 10.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.8.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |