PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.036
EPSS Ranking 87.5%