CVE-2021-23400
PoC ×2—CVSS 3.1
8.8 high
EPSS
1%p71
Published
()
Modified
Description
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
- Vendors
- nodemailer
- Products
- nodemailer
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.