CVE-2016-10034 | Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 zend-mail setFrom command injection (EDB-40979 / Nessus ID 108931)
A vulnerability has been found in Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 and classified as critical. This vulnerability affects the function setFrom of the component zend-mail. The manipulation leads to command injection.
This vulnerability was named CVE-2016-10034. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.