SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-8476

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand…

MEDIUM 5.0EPSS 1.99%

Does this matter?

Lower severity and a low EPSS score (1.99%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.99% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
debian/debian linux · phpmailer project/phpmailer
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.