VULNERABILITY INTELLIGENCE

CVE-2012-0796

CVSS score4 MEDIUM
EPSS probability1.68%
CISA KEVNot currently listed
Published2012-07-17
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:S/C:N/I:P/A:N

Description

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

Weakness classification

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Primary references