Intel

AIKIDO-2025-10031

webklex/php-imap is vulnerable to Authentication Bypass by Spoofing

Authentication Bypass by Spoofing Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 20, 2025

81

High Risk

This Affects:

phpwebklex/php-imap
1.4.2 - 6.0.0
Fixed in 6.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by an insecure identity validation that may lead to email spoofing when php-imap recognizes the legitimate sender but lacks the envelope-from attribute in the headers, making it possible to spoof that attribute. This vulnerability enables attackers to forge sender identities, facilitating phishing and social engineering attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

webklex/php-imap is vulnerable to Authentication Bypass by Spoofing in versions 1.4.2 - 6.0.0.

How to fix this

Upgrade the webklex/php-imap library to the patch version.