CVE-2017-11503
Ubuntu Security Notice USN-5956-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.
PHPMailer versiĆ³n 5.2.23 tiene XSS en los campos "From Email Address" y "To Email Address" de code_generator.php.
Dawid Golunski discovered that PHPMailer was not properly escaping user input data used as arguments to functions executed by the system shell. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. It was discovered that PHPMailer was not properly escaping characters in certain fields of the code_generator.php example code. An attacker could possibly use this issue to conduct cross-site scripting attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-20 CVE Reserved
- 2017-07-20 CVE Published
- 2018-03-27 First Exploit
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99293 | Third Party Advisory | |
http://www.securitytracker.com/id/1039026 | Third Party Advisory | |
https://github.com/PHPMailer/PHPMailer | Product |
URL | Date | SRC |
---|---|---|
https://github.com/wizardafric/download | 2018-03-27 | |
https://cxsecurity.com/issue/WLB-2017060181 | 2024-08-05 | |
https://packetstormsecurity.com/files/143138/phpmailer-xss.txt | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.24 | 2019-05-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phpmailer Project Search vendor "Phpmailer Project" | Phpmailer Search vendor "Phpmailer Project" for product "Phpmailer" | 5.2.23 Search vendor "Phpmailer Project" for product "Phpmailer" and version "5.2.23" | - |
Affected
|