#VU54170 Input validation error in PHPMailer - CVE-2021-34551
Published: June 16, 2021
PHPMailer
phpmailer.sourceforge.net
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the setLanguage() method when processing the $lang_path parameter on a Windows system. A remote attacker can pass specially crafted input to the application, set a UNC path via the affected parameter and execute arbitrary PHP code on the system.