CVE-2016-10074 | SwiftMailer 5.4.5-DEV mail -f command injection (EDB-40972 / Nessus ID 96636)
A vulnerability was found in SwiftMailer 5.4.5-DEV. It has been declared as critical. This vulnerability affects the function mail. The manipulation of the argument -f with the input "Attacker -Param2 -Param3"@test.com leads to command injection.
This vulnerability was named CVE-2016-10074. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.