Vulnerability record · CVE-2016-10045 · published 30 December 2016
CVE-2016-10045: PHPMailer isMail transport argument injection enables remote code execution
Phpmailer Project · Phpmailer
PHPMailer before 5.2.20 fails to properly neutralize shell metacharacters in the isMail transport, because escapeshellarg interacts incorrectly with PHP's internal escaping of the mail() function. An attacker who controls an address field passed to the mailer can inject extra arguments to the underlying sendmail command. This is a bypass of the incomplete fix for CVE-2016-10033, so systems patched only for that earlier flaw remain exposed.
Description
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code and a very high EPSS score make this an urgent patch target despite its age.
What it is
PHPMailer before 5.2.20 fails to properly neutralize shell metacharacters in the isMail transport, because escapeshellarg interacts incorrectly with PHP's internal escaping of the mail() function. An attacker who controls an address field passed to the mailer can inject extra arguments to the underlying sendmail command. This is a bypass of the incomplete fix for CVE-2016-10033, so systems patched only for that earlier flaw remain exposed.
Impact
An unauthenticated remote attacker can pass extra parameters to the mail command and execute arbitrary code in the context of the web server. That typically yields full compromise of the application and its data.
Attack surface
Reached over the network through any application code path that feeds attacker-influenced input (such as a sender or recipient address) into PHPMailer's isMail transport. The CVSS vector shows no privileges and no user interaction required, so exposure depends on whether such a path is reachable.
Exploitation
Not listed in CISA KEV, but EPSS is 0.9758 (99.9th percentile) and multiple references carry Exploit tags, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, indicating public exploit code exists.
What to do
- Upgrade PHPMailer to 5.2.20 or later, which contains the corrected fix for the CVE-2016-10033 escaping issue.
- Update bundled copies in WordPress, Joomla and other applications, since they ship their own PHPMailer versions.
- Where the isMail transport is not required, switch to SMTP transport to remove the shell invocation path.
- Validate and reject shell metacharacters in any address or header value passed to the mailer.
- Inventory applications and libraries embedding PHPMailer to find unpatched copies.
Detection
- Search web server and application logs for mail command arguments containing shell metacharacters or unexpected flags.
- Monitor for outbound connections or child processes spawned by the web server user that are unusual for the application.
- Check file integrity and process creation events on hosts running PHP applications that use PHPMailer.
- Scan deployed code bases for PHPMailer versions below 5.2.20.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-10045 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10045), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.