← Vulnerability feed

Vulnerability record · CVE-2017-11503 · published 20 July 2017

CVE-2017-11503: Phpmailer project phpmailer cross-site scripting vulnerability

Phpmailer Project · Phpmailer

PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.

6.1 CVSS 3.0 Medium EPSS 2.4% · top 16.5% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/99293/ Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039026 Third Party AdvisoryVDB Entry
https://cxsecurity.com/issue/WLB-2017060181 ExploitThird Party Advisory
https://packetstormsecurity.com/files/143138/phpmailer-xss.txt ExploitThird Party AdvisoryVDB Entry
https://github.com/PHPMailer/PHPMailer Product
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.24 PatchRelease NotesThird Party Advisory
http://www.securityfocus.com/bid/99293/ Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039026 Third Party AdvisoryVDB Entry
https://cxsecurity.com/issue/WLB-2017060181 ExploitThird Party Advisory
https://packetstormsecurity.com/files/143138/phpmailer-xss.txt ExploitThird Party AdvisoryVDB Entry

Track CVE-2017-11503 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed9.8CVE-2020-36326Phpmailer project phpmailer deserialization of untrusted data vulnerabilityPHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV…EPSS 3.1%9.8CVE-2016-10045PHPMailer isMail transport argument injection enables remote code executionPHPMailer before 5.2.20 fails to properly neutralize shell metacharacters in the isMail transport, because escapeshellarg interacts incorrectly with …EPSS 98%analysed8.8CVE-2018-19296Phpmailer project phpmailer deserialization of untrusted data vulnerabilityPHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.EPSS 2.2%8.1CVE-2021-3603Phpmailer project phpmailer inclusion from untrusted sphere vulnerabilityPHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's …EPSS 2.3%8.1CVE-2021-34551Phpmailer project phpmailer unrestricted file upload vulnerabilityPHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.EPSS 2.8%7.5CVE-2020-13625Phpmailer project phpmailer vulnerabilityPHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the f…EPSS 3.8%5.5CVE-2017-5223Phpmailer project phpmailer information exposure vulnerabilityAn issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an em…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2017-11503), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.