// For flags

CVE-2020-36326

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

PHPMailer versión 6.1.8 hasta la versión 6.4.0 permite la inyección de objetos a través de Phar Deserialization vía addAttachment con un nombre de ruta UNC. NOTA: esto es similar a CVE-2018-19296, pero surgió porque la versión 6.1.8 corrigió un problema de funcionalidad en el que los nombres de ruta UNC siempre se consideraban ilegibles por PHPMailer, incluso en contextos seguros. Como efecto secundario no intencionado, esta corrección eliminó el código que bloqueaba la explotación de addAttachment

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-04-28 CVE Reserved
  • 2021-04-28 CVE Published
  • 2024-03-20 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Phpmailer Project
Search vendor "Phpmailer Project"
Phpmailer
Search vendor "Phpmailer Project" for product "Phpmailer"
>= 6.1.8 <= 6.4.0
Search vendor "Phpmailer Project" for product "Phpmailer" and version " >= 6.1.8 <= 6.4.0"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 3.7 < 3.7.36
Search vendor "Wordpress" for product "Wordpress" and version " >= 3.7 < 3.7.36"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 3.8 < 3.8.36
Search vendor "Wordpress" for product "Wordpress" and version " >= 3.8 < 3.8.36"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 3.9 < 3.9.34
Search vendor "Wordpress" for product "Wordpress" and version " >= 3.9 < 3.9.34"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.0 < 4.0.33
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.0 < 4.0.33"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.1 < 4.1.33
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.1 < 4.1.33"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.2 < 4.2.30
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.2 < 4.2.30"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.3 < 4.3.26
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.3 < 4.3.26"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.4 < 4.4.25
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.4 < 4.4.25"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.5 < 4.5.24
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.5 < 4.5.24"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.6 < 4.6.21
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.6 < 4.6.21"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.7 < 4.7.21
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.7 < 4.7.21"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.8 < 4.8.17
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.8 < 4.8.17"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 4.9 < 4.9.18
Search vendor "Wordpress" for product "Wordpress" and version " >= 4.9 < 4.9.18"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.0 < 5.0.13
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.0 < 5.0.13"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.1 < 5.1.10
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.1 < 5.1.10"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.2 < 5.2.11
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.2 < 5.2.11"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.3 < 5.3.8
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.3 < 5.3.8"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.4 < 5.4.6
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.4 < 5.4.6"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.5 < 5.5.5
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.5 < 5.5.5"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.6 < 5.6.4
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.6 < 5.6.4"
-
Affected
Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
>= 5.7 < 5.7.2
Search vendor "Wordpress" for product "Wordpress" and version " >= 5.7 < 5.7.2"
-
Affected