Envato reported this vulnerability:
Update to PHPMailer 5.2.22
Already reported from: https://developer.joomla.org/security-centre/668-20161205-phpmailer-security-advisory.html
Just posting here to make it a higher priority.
Labels |
Added:
?
|
Or do i miss something?
Nope. Pretty normal "hey, these guys issued a security release, you should do something" issue report. Happens with most repos.
Closing though. No action required, core has already updated the library.
Status | New | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2017-01-18 13:26:06 |
Closed_By | ⇒ | mbabker |
Alpha 1 was tagged before the PHPMailer vulnerabilities were disclosed/patched, kinda hard to include something from the future
Hmm did you read the report from the JSST?
The Joomla Core is not affected by this issue and the next update is going to fix that see: https://github.com/joomla/joomla-cms/blob/staging/libraries/vendor/phpmailer/phpmailer/VERSION
Or do i miss something?