DRUPAL-CONTRIB-2024-014

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/symfony_mailer_lite/DRUPAL-CONTRIB-2024-014.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-014
Aliases
Published
2024-02-28T18:36:35Z
Modified
2026-09-10T03:46:12Z
Summary
[none]
Details

The module doesn’t sufficiently protect against malicious links, which means an attacker can trick an administrator into performing unwanted actions.

This vulnerability is mitigated by the fact that the set of unwanted actions is limited to specific configurations.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/symfony_mailer_lite

Package

Name
drupal/symfony_mailer_lite
Purl
pkg:composer/drupal/symfony_mailer_lite?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.6
Database specific
Show details
{
    "constraint": "<1.0.6"
}

Database specific

affected_versions
"<1.0.6"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/symfony_mailer_lite/DRUPAL-CONTRIB-2024-014.json"