in2code/powermail is vulnerable to Server-Side Template Injection (SSTI)
95
Critical Risk
The extension renders the submitted value of a form field configured as the sender name (and similar sender fields) as Fluid template source without sanitization. Someone submitting a normal form can inject Fluid template syntax and invoke arbitrary ViewHelpers, exposing server configuration, environment variables, and application source, and potentially executing arbitrary code. The parsing happens without authentication and without any ViewHelper allowlist. The fix restricts frontend Fluid parsing to configured keys, allowlists namespaces and ViewHelpers, neutralizes unsafe modifiers, and removes persistent caching of visitor-controlled templates.
You are affected if you are using a version that falls within the vulnerable range and your forms use a field configured as the sender name (or a comparable sender field) whose submitted value is rendered through Fluid.
in2code/powermail is vulnerable to Server-Side Template Injection (SSTI) in versions 3.4.0 - 10.9.2, 11.0.0 - 12.6.0 and 13.0.0 - 13.2.0.
Upgrade the in2code/powermail library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.