← Vulnerability feed

Vulnerability record · CVE-2017-5223 · published 16 January 2017

CVE-2017-5223: Phpmailer project phpmailer information exposure vulnerability

Phpmailer Project · Phpmailer

An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to /, meaning that relative image URLs get treated as absolute local file paths and added as attachments. To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.

5.5 CVSS 3.0 Medium EPSS 2.2% · top 18.4% CWE-200 · Information exposure
5.5CVSS 3.0 base score, v2 2.1
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to /, meaning that relative image URLs get treated as absolute local file paths and added as attachments. To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed9.8CVE-2020-36326Phpmailer project phpmailer deserialization of untrusted data vulnerabilityPHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV…EPSS 3.1%9.8CVE-2016-10045PHPMailer isMail transport argument injection enables remote code executionPHPMailer before 5.2.20 fails to properly neutralize shell metacharacters in the isMail transport, because escapeshellarg interacts incorrectly with …EPSS 98%analysed8.8CVE-2018-19296Phpmailer project phpmailer deserialization of untrusted data vulnerabilityPHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.EPSS 2.2%8.1CVE-2021-3603Phpmailer project phpmailer inclusion from untrusted sphere vulnerabilityPHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's …EPSS 2.3%8.1CVE-2021-34551Phpmailer project phpmailer unrestricted file upload vulnerabilityPHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.EPSS 2.8%7.5CVE-2020-13625Phpmailer project phpmailer vulnerabilityPHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the f…EPSS 3.8%6.1CVE-2017-11503Phpmailer project phpmailer cross-site scripting vulnerabilityPHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2017-5223), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.