PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.044
EPSS Ranking 89.0%