Permalink
Browse files

5.2.22

1 parent ad4cb09 commit 5d88839afca84049cc35179b1b3ba839f1d20696 @Synchro Synchro committed Jan 6, 2017
Showing with 11 additions and 4 deletions.
  1. +2 −0 SECURITY.md
  2. +1 −1 VERSION
  3. +5 −0 changelog.md
  4. +1 −1 class.pop3.php
  5. +2 −2 class.smtp.php
View
@@ -2,6 +2,8 @@
Please disclose any vulnerabilities found responsibly - report any security problems found to the maintainers privately.
+PHPMailer versions prior to 5.2.22 (released January 2017) have a local file disclosure vulnerability if content passed into `msgHTML()` is sourced from unfiltered user input. Also note that `addAttachment` (just like `file_get_contents`, `passthru`, `unlink`, etc) should not be passed user-sourced params either!
+
PHPMailer versions prior to 5.2.20 (released December 28th 2016) are vulnerable to [CVE-2016-10045](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10045) a remote code execution vulnerability, responsibly reported by [Dawid Golunski](https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html), and patched by Paul Buonopane (@Zenexer).
PHPMailer versions prior to 5.2.18 (released December 2016) are vulnerable to [CVE-2016-10033](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10033) a remote code execution vulnerability, responsibly reported by [Dawid Golunski](http://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html).
View
@@ -1 +1 @@
-5.2.21
+5.2.22
View
@@ -1,5 +1,10 @@
# ChangeLog
+## Version 5.2.22 (January 5th 2017)
+* **SECURITY** Fix local file disclosure vulnerability if content passed to `msgHTML()` is sourced from unfiltered user input.
+* Add simple contact form example
+* Emoji in test content
+
## Version 5.2.21 (December 28th 2016)
* Fix missed number update in version file - no functional changes
View
@@ -34,7 +34,7 @@ class POP3
* @var string
* @access public
*/
- public $Version = '5.2.21';
+ public $Version = '5.2.22';
/**
* Default POP3 port number.
View
@@ -30,7 +30,7 @@ class SMTP
* The PHPMailer SMTP version number.
* @var string
*/
- const VERSION = '5.2.21';
+ const VERSION = '5.2.22';
/**
* SMTP line break constant.
@@ -81,7 +81,7 @@ class SMTP
* @deprecated Use the `VERSION` constant instead
* @see SMTP::VERSION
*/
- public $Version = '5.2.21';
+ public $Version = '5.2.22';
/**
* SMTP server port number.

0 comments on commit 5d88839

Please sign in to comment.