CVE-2017-11503: PHPMailer Project PHPMailer
Medium severity, CVSS 6.1. EPSS: 2.4% chance of exploitation in the next 30 days.
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.
Affected products
- PHPMailer Project PHPMailer: version 5.2.23 only
Published 2017-07-20. Last modified 2026-06-17.