Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squishdot Mail_HTML CRLF注入漏洞
Vulnerability Description
template in Squishdot 1.5.0及之前版本的mail_html模板没有正确验证(1) email和(2) title变量,从而使得远程攻击者通过注入SMTP报头(可能是由于CRLF注入漏洞)来绕过垃圾邮件过滤器。
CVSS Information
N/A
Vulnerability Type
N/A