Command Injection in aiosmtpd - CVE-2024-27305
Published: March 15, 2024
aiosmtpd
aio-libs
Description
The vulnerability allows a remote attacker to perform SMTP smuggling attack.
The vulnerability exists due to insufficient filtration of user supplied input when parsing headers in email messages. A remote attacker can send a specially crafted email message and smuggle or spoof e-mails with fake sender addresses, allowing advanced phishing attacks.