Arbitrary additional email headers can be injected via crafted From or Sender headers.
Fixed in 2.2.1
Filter user-supplied values prior to using them in From or Sender properties.
https://nvd.nist.gov/vuln/detail/CVE-2012-0796
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2022-10-06T21:25:46Z",
"nvd_published_at": "2012-07-17T10:20:00Z",
"severity": "HIGH"
}