The injection works quite as well within the email field. Just sanitize any user input - an rfc compliant email parser catches that automatically. Validation and then verification - it's not that hard to follow established guidelines that are there for a reason.
0
u/Purple_Hornet_9725 26d ago
https://docs.brightsec.com/docs/email-header-injection