Project: 
Date: 
2018-October-17
Vulnerability: 
Remote Code Execution
Description: 

The MIME Mail module allows to send MIME-encoded e-mail messages with embedded images and attachments.

The module doesn't sufficiently sanitized some variables for shell arguments when sending email, which could lead to arbitrary remote code execution.

This issue is related to the Drupal Core release SA-CORE-2018-006.

Solution: 

Install the latest version:

Also see the Mime Mail project page.

Reported By: 
Fixed By: 
Coordinated By: