{"id":"GHSA-4x5h-cr29-fhp6","summary":"Local file disclosure in PHPMailer","details":"An issue was discovered in PHPMailer before 5.2.22. PHPMailer&#39;s `msgHTML` method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to `/`, meaning that relative image URLs get treated as absolute local file paths and added as attachments. To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.\n\n### Impact\nArbitrary local files can be attached to email messages.\n\n### Patches\nFixed in 5.2.22\n\n### Workarounds\nValidate input before using user-supplied file paths.\n\n### References\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-5223\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a private issue in [the PHPMailer project](https://github.com/PHPMailer/PHPMailer)","aliases":["CVE-2017-5223"],"modified":"2024-02-16T05:22:38.352372Z","published":"2020-03-05T22:09:10Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-03-05T22:07:31Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-4x5h-cr29-fhp6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5223"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/phpmailer/phpmailer/CVE-2017-5223.yaml"},{"type":"WEB","url":"https://github.com/PHPMailer/PHPMailer/blob/master/SECURITY.md"},{"type":"WEB","url":"https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.22"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/43056"},{"type":"WEB","url":"http://kalilinux.co/2017/01/12/phpmailer-cve-2017-5223-local-information-disclosure-vulnerability-analysis"},{"type":"WEB","url":"http://www.securityfocus.com/bid/95328"}],"affected":[{"package":{"name":"phpmailer/phpmailer","ecosystem":"Packagist","purl":"pkg:composer/phpmailer/phpmailer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.2.22"}]}],"versions":["v5.2.10","v5.2.11","v5.2.12","v5.2.13","v5.2.14","v5.2.15","v5.2.16","v5.2.17","v5.2.18","v5.2.19","v5.2.2","v5.2.20","v5.2.21","v5.2.4","v5.2.5","v5.2.6","v5.2.7","v5.2.8","v5.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-4x5h-cr29-fhp6/GHSA-4x5h-cr29-fhp6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}