Jump to content

PHPMailer vulnerability prior to v5.2.18


sentq

Recommended Posts

there is a vulnerability discovered in PHPMailer, WHMCS v7.1 use (v5.2.16)

 

the critical vulnerability (CVE-2016-10033) allows an attacker to remotely execute arbitrary code in the context of the web server and compromise the target web application.
All versions of PHPMailer before the critical release of PHPMailer 5.2.18 are affected, so web administrators and developers are strongly recommended to update to the patched release.

 

http://thehackernews.com/2016/12/phpmailer-security.html

Link to comment
Share on other sites

Here is an update from our development team:

 

The WHMCS development team has reviewed the recent changes to PHPMailer and the related information regarding CVE-2016-10033. While at this time we do not believe the deficiency in PHPMailer is exposed in WHMCS due to our own validation of user input, this CVE represents a serious issue for PHPMailer and therefore to mitigate any undiscovered risk we intend to deliver updates to PHPMailer for all versions of WHMCS in active and long term support. We anticipate delivering updates for WHMCS 7.x within the next 48 hours, and 6.2 and 6.3 shortly therafter.
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated