CVE-2017-20187
Description
UNSUPPORTED WHEN ASSIGNED A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads to injection. Upgrading to version 0.3.1 is able to address this issue. The patch is identified as 500d340e1f6421007413cc08a8383475221c2604. It is recommended to upgrade the affected component. VDB-244482 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
floriangaerber/magnesiumPackagist | < 0.3.1 | 0.3.1 |
Affected products
3- Magnesium-PHP/Magnesium-PHPdescription
Patches
Vulnerability mechanics
References
6- github.com/floriangaerber/Magnesium-PHP/commit/500d340e1f6421007413cc08a8383475221c2604nvdPatchWEB
- github.com/advisories/GHSA-8pp6-5qpw-85g3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-20187ghsaADVISORY
- vuldb.comnvdThird Party AdvisoryWEB
- vuldb.comnvdThird Party AdvisoryWEB
- github.com/floriangaerber/Magnesium-PHP/releases/tag/v0.3.1nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.