UBUNTU-CVE-2017-11503

Source
https://ubuntu.com/security/CVE-2017-11503
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-11503.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-11503
Upstream
Downstream
USN (2)
Related
Published
2017-07-20T23:29:00Z
Modified
2026-02-04T04:26:00Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.

References

Affected packages

Ubuntu:Pro:16.04:LTS / libphp-phpmailer

Package

Name
libphp-phpmailer
Purl
pkg:deb/ubuntu/libphp-phpmailer@5.2.14+dfsg-1ubuntu0.1~esm2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.14+dfsg-1ubuntu0.1~esm2

Affected versions

5.*
5.2.10+dfsg-1
5.2.14+dfsg-1
5.2.14+dfsg-1build1
5.2.14+dfsg-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "libphp-phpmailer",
            "binary_version":  "5.2.14+dfsg-1ubuntu0.1~esm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-11503.json"

Ubuntu:Pro:18.04:LTS / libphp-phpmailer

Package

Name
libphp-phpmailer
Purl
pkg:deb/ubuntu/libphp-phpmailer@5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm2

Affected versions

5.*
5.2.14+dfsg-2.3
5.2.14+dfsg-2.3+deb9u1build0.18.04.1
5.2.14+dfsg-2.3+deb9u2build0.18.04.1
5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm1

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "libphp-phpmailer",
            "binary_version":  "5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-11503.json"