CVE-2017-20187
Summary
| CVE | CVE-2017-20187 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-05 21:15:00 UTC |
| Updated | 2023-11-14 14:44:00 UTC |
| Description | ** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads to injection. Upgrading to version 0.3.1 is able to address this issue. The patch is identified as 500d340e1f6421007413cc08a8383475221c2604. It is recommended to upgrade the affected component. VDB-244482 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2017-20187: Magnesium-PHP Base.php formatEmailString injection |
MISC |
vuldb.com |
|
| Login required |
MISC |
vuldb.com |
|
| Fix exploit of user's names/emails breaking "To" · floriangaerber/Magnesium-PHP@500d340 · GitHub |
MISC |
github.com |
|
| Release v0.3.1 · floriangaerber/Magnesium-PHP · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995846 PHP (Composer) Security Update for floriangaerber/magnesium (GHSA-8pp6-5qpw-85g3)