—
DRUPAL-CONTRIB-2024-014
Details
The module doesn’t sufficiently protect against malicious links, which means an attacker can trick an administrator into performing unwanted actions.
This vulnerability is mitigated by the fact that the set of unwanted actions is limited to specific configurations.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/symfony_mailer_lite
Introduced in:
0Fixed in: 1.0.6Upgrade drupal/symfony_mailer_lite to 1.0.6 or newer (ecosystem packagist:https://packages.drupal.org/8).