formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.
- http://securityreason.com/securityalert/2710
No PoCs found on GitHub currently.