diff --git a/htdocs/core/class/CMailFile.class.php b/htdocs/core/class/CMailFile.class.php index 1b5faeff52e..9ec895926a0 100644 --- a/htdocs/core/class/CMailFile.class.php +++ b/htdocs/core/class/CMailFile.class.php @@ -420,7 +420,20 @@ class CMailFile //$this->message->setFrom(array('john@doe.com' => 'John Doe')); if (!empty($from)) { try { - $result = $this->message->setFrom($this->getArrayAddress($from)); + if (! empty($conf->global->MAIN_FORCE_DISABLE_MAIL_SPOOFING)) { + // Prevent email spoofing for smtp server with a strict configuration + $regexp = '/([a-z0-9_\.\-\+])+\@(([a-z0-9\-])+\.)+([a-z0-9]{2,4})+/i'; // This regular expression extracts all emails from a string + $emailMatchs = preg_match_all($regexp, $from, $adressEmailFrom); + $adressEmailFrom = reset($adressEmailFrom); + if ($emailMatchs !== false && filter_var($conf->global->MAIN_MAIL_SMTPS_ID, FILTER_VALIDATE_EMAIL) && $conf->global->MAIN_MAIL_SMTPS_ID !== $adressEmailFrom) + { + $result = $this->message->setFrom($conf->global->MAIN_MAIL_SMTPS_ID); + } else { + $result = $this->message->setFrom($this->getArrayAddress($from)); + } + } else { + $result = $this->message->setFrom($this->getArrayAddress($from)); + } } catch (Exception $e) { $this->errors[] = $e->getMessage(); }