PHPFormMail is prone to an HTML injection vulnerability. This issue is due to an input validation error related to a hidden field for field aliases. This vulnerability could allow for various attacks, although the software does not appear to use cookies or support user sessions, so session hijacking may not be possible.
PHPFormMail is prone to an HTML injection vulnerability. This issue is due to an input validation error related to a hidden field for field aliases. This vulnerability could allow for various attacks, although the software does not appear to use cookies or support user sessions, so session hijacking may not be possible.