SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-0712

mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.

MEDIUM 5.0EPSS 1.61%

Does this matter?

Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.

Description

mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.61% probability · 75th percentile
CISA KEV
Not listed
Affected
squishdot/squishdot
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.