CRITICAL🇵🇱 Wersja polska

CVE-2020-36326

CVSS 9.8v3.1pub. 2021-04-28upd. 2024-11-21

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Phpmailer Project Phpmailer

    APP
    Phpmailer Project
    6.1.8 – 6.4.0
  • WordPress

    APP
    Wordpress
    3.7 – 3.7.36 (excl.)3.8 – 3.8.36 (excl.)3.9 – 3.9.34 (excl.)4.0 – 4.0.33 (excl.)4.1 – 4.1.33 (excl.)4.2 – 4.2.30 (excl.)4.3 – 4.3.26 (excl.)4.4 – 4.4.25 (excl.)4.5 – 4.5.24 (excl.)4.6 – 4.6.21 (excl.)4.7 – 4.7.21 (excl.)4.8 – 4.8.17 (excl.)4.9 – 4.9.18 (excl.)5.0 – 5.0.13 (excl.)5.1 – 5.1.10 (excl.)+ 6 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2026-63030CRITICAL9.8⚠ KEVPL ✓same product

WordPress: RCE przez route confusion w REST API i SQL Injection

CVE-2016-10033CRITICAL9.8⚠ KEVPL ✓same product

PHPMailer — RCE poprzez argument injection w funkcji mailSend

CVE-2020-28035CRITICAL9.8PL ✓same product

Privilege escalation w WordPress przez XML-RPC (przed wersją 5.5.2)

CVE-2020-28032CRITICAL9.8PL ✓same product

WordPress — niebezpieczna deserializacja w FilteredIterator

CVE-2020-28036CRITICAL9.8PL ✓same product

WordPress: privilege escalation przez XML-RPC przy komentowaniu wpisów