Security
Loading…

CVE-2016-10033

UNKNOWNKnown Exploited
Description

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

Timeline
Published:July 7th, 2025 12:00 AM
Last modified:July 7th, 2025 12:00 AM
Added to KEV:July 7th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

PHP

Products

PHPMailer
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute