版本 5.1.3 之前的 aiosmtplib 未能正确验证调用方提供的电子邮件地址,攻击者可以将 ESMTP 参数注入到 MAIL FROM 和 RCPT TO 命令中。攻击者可以构造包含空格和尖括号的恶意地址,从而向信封命令添加 AUTH、NOTIFY 或 ORCPT 等参数,以此伪造已认证的身份,或强制向第三方发送送达通知。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cole | aiosmtplib | 0 ~ 5.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet