Hi,
I recently moved to a new host (A2 Hosting) - they run regular security checks on installed software and sent me a warning email about a code injection vulnerability in phpmailer. I'm running projeqtor 9.2.1. Their patch system (patchman) patched the software.
Received form A2 Hosting
Hello,
As part of our commitment to providing you with a secure hosting environment, we performed an automated scan of your domain(s)
It appears patches are available for application(s) installed in the following path(s):Code injection vulnerability in PHPMailer
/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/projeqtor/external/PHPMailer/src/PHPMailer.phpIf you are working with a development partner, please forward this email on to them as they will be able to take care of the update for you. Otherwise, we will automatically apply the above patches within seven days.
Click here to learn more about our perpetual security scans: https://www.a2hosting.com/kb/cpanel/advanced-features/patchman
Best regards,
The A2 Hosting Support Team
Hi,
Thanks for sharing this issue with external Library PHPMailer.
Did you have a patch file with the notification ?
If so, could you please post it here ?
We have the opportunity to upgrade the library from V6.0.6 to V6.5.0 but would like to check if this leak is fixed on this version.
Thanks.
Hi,
No, I don't have the patch file - A2 Hosting's patchman system patched it automatically. If it helps, I can send you the patched file - it should be possible to work out the changes using diff.
Yes, please post the patched file.
Here you go. I browsed the phpmailer subdirectories, and that appears to be the only file that was patched.
Hi,
The patch is the new version from PHPMAiler repository, so we'ill migrate the library to the newest version that includes the patch.
Thanks.