Arbitrary Code Execution via Email From Field in CodeIgniter

Arbitrary Code Execution via Email From Field in CodeIgniter

CVE-2016-10131 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.

Learn more about our Web Application Penetration Testing UK.