Hosts vulnerable to CVE-2020-36326

CVE-2020-36326 — severity critical, CVSS 9.8 — 3 affected hosts indexed by QROS Explore.

About CVE-2020-36326

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe

Showing 3 of 3 hosts, ranked by risk score.

Search all CVE-2020-36326 hosts in Explore

Open in Explore →