—
DRUPAL-CONTRIB-2023-031
Details
The module doesn’t sufficiently protect against malicious links, which means an attacker can trick an administrator into performing unwanted actions.
This vulnerability is mitigated by the fact that the set of unwanted actions is limited to specific configurations.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/symfony_mailer
Introduced in:
0Fixed in: 1.2.2Upgrade drupal/symfony_mailer to 1.2.2 or newer (ecosystem packagist:https://packages.drupal.org/8).