The mail transport (aka SwiftTransportMailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:swiftmailer:swiftmailer:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "5.4.4"
}
]
}