CVE-2015-3154

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
27/01/2020
Last modified:
30/01/2020

Description

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:* 1.12.12 (excluding)
cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:* 2.3.0 (including) 2.3.8 (excluding)
cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:* 2.4.0 (including) 2.4.1 (excluding)


References to Advisories, Solutions, and Tools