WebsiteBaker Logo
  • *
  • Templates
  • Help
  • Add-ons
  • Download
  • Home
*
Welcome, Guest. Please login or register.

Login with username, password and session length
 

News


WebsiteBaker 2.13.6 is now available!


Will it continue with WB? It goes on! | Geht es mit WB weiter? Es geht weiter!
https://forum.websitebaker.org/index.php/topic,32340.msg226702.html#msg226702


The forum email address board@websitebaker.org is working again
https://forum.websitebaker.org/index.php/topic,32358.0.html


R.I.P Dietmar (luisehahne) and thank you for all your valuable work for WB
https://forum.websitebaker.org/index.php/topic,32355.0.html


* Support WebsiteBaker

Your donations will help to:

  • Pay for our dedicated server
  • Pay for domain registration
  • and much more!

You can donate by clicking on the button below.


  • Home
  • Help
  • Search
  • Login
  • Register

  • WebsiteBaker Community Forum »
  • WebsiteBaker Support (2.12.x) »
  • General Help & Support »
  • Ist class.phpmailer.php anfällig oder nicht?
  • Print
Pages: [1]   Go Down

Author Topic: Ist class.phpmailer.php anfällig oder nicht?  (Read 9347 times)

Offline CodeALot

  • Posts: 579
  • Gender: Male
Ist class.phpmailer.php anfällig oder nicht?
« on: May 27, 2021, 11:03:56 AM »
Mir ist aufgefallen, dass sich in 2.13 das gesamte include/phpmailer geändert hat. Es gibt keine class.phpmailer.php mehr.

Viele Sites laufen allerdings noch mit 2.12, die class.phpmailer.php haben. Ich habe EINE Hostingfirma, die behauptet, dass diese PHP-Datei eine Code-Injection-Schwachstelle enthält.
Ich kann sie nicht sehen. Kann mir jemand sagen, ob es tatsächlich ein Problem mit class.phpmailer.php in WB 2.12 gibt?


I noticed that in 2.13 the whole include/phpmailer has changed. There is no class.phpmailer.php anymore.

Many sites still run 2.12 though, which has class.phpmailer.php. I have ONE hosting company that claims that this PHP-file contains a code-injection vulnerability.
I can't see it. Can anyone tell me if their is indeed a problem with class.phpmailer.php in WB 2.12?
Logged

Offline hgs

  • WebsiteBaker Org e.V.
  • **
  • Posts: 1884
    • EFG MG
Re: Ist class.phpmailer.php anfällig oder nicht?
« Reply #1 on: May 27, 2021, 02:17:17 PM »
Antwort lautet, Ja

Nachlesen kann man es in der Datei:
SECURITY.md im Verzeichnis: /include/phpmailer/phpmailer/

Hier ein kleiner Auszug der letzten beiden Meldungen:
Quote
PHPMailer versions 6.1.5 and earlier contain an output escaping bug that occurs in `Content-Type` and `Content-Disposition` when filenames passed into `addAttachment` and other methods that accept attachment names contain double quote characters, in contravention of RFC822 3.4.1. No specific vulnerability has been found relating to this, but it could allow file attachments to bypass attachment filters that are based on matching filename extensions. Recorded as [CVE-2020-13625](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-13625). Reported by Elar Lang of Clarified Security.

PHPMailer versions prior to 6.0.6 and 5.2.27 are vulnerable to an object injection attack by passing `phar://` paths into `addAttachment()` and other functions that may receive unfiltered local paths, possibly leading to RCE. Recorded as [CVE-2018-19296](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-19296). See [this article](https://knasmueller.net/5-answers-about-php-phar-exploitation) for more info on this type of vulnerability. Mitigated by blocking the use of paths containing URL-protocol style prefixes such as `phar://`. Reported by Sehun Oh of cyberone.kr.

In der WebsiteBaker-Version 2.13 wird die phpmailer-Version 6.3.0 verwendet.
Die letzten Test sind bis jetzt alle ohne Befund, sodass wir kurz vor Veröffentlichung der neuen WebsiteBaker Version 2.13 stehen.

« Last Edit: May 27, 2021, 03:05:10 PM by hgs »
Logged
LG Harald

"Fange nie an, aufzuhören - höre nie auf, anzufangen." Marcus Tullius Cicero (106-43 v.Chr.)

"Never begin to stop - never stop beginning." Marcus Tullius Cicero (106-43 BC)

  • Print
Pages: [1]   Go Up
  • WebsiteBaker Community Forum »
  • WebsiteBaker Support (2.12.x) »
  • General Help & Support »
  • Ist class.phpmailer.php anfällig oder nicht?
 

  • SMF 2.0.19 | SMF © 2017, Simple Machines
  • XHTML
  • RSS
  • WAP2