dongwei4652 2016-12-27 21:55
The announcement I am referring to was posted at:

I have used code like this in many websites:

$mail = new PHPMailer(true);
$mail->SetFrom('', 'My Site');
$mail->AddReplyTo( $contact_email, "$contact_name" );
$mail->Subject = $subject;
$mail->AltBody = $mail_text;
$result = $mail->Send();

Am I safe from the vulnerability because my from address is hard-coded? Should I worry about the reply-to address, which comes from user input? I do validate it with filter_var, but if I understand correctly, a from address can pass validation and still inject code because spaces are technically allowed in email addresses.

  • drctyr2869 2016-12-27 23:04

    Yes, you are safe.

    As Sammitch said, you should never use a user-supplied from address anyway because it will be forgery and you will fail SPF checks. This is mentioned in the PHPMailer docs and in many answers on SO.

