mail_html template in Squishdot 1.5.0 and previous versions does not properly validate the (1) email and (2) title variables, which allows remote malicious users to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
squishdot squishdot 1.0.0 |
||
squishdot squishdot 1.1.0 |
||
squishdot squishdot 1.2.1 |
||
squishdot squishdot 1.4.0 |
||
squishdot squishdot 1.4.1 |
||
squishdot squishdot 1.5.0 |
||
squishdot squishdot 0.7.2 |