Description
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2244-1 | libphp-phpmailer security update |
Debian DLA |
DLA-2306-1 | libphp-phpmailer security update |
EUVD |
EUVD-2020-0422 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message. |
Github GHSA |
GHSA-f7hx-fqxw-rvvj | Insufficient output escaping of attachment names in PHPMailer |
Ubuntu USN |
USN-4505-1 | PHPMailer vulnerability |
Ubuntu USN |
USN-5956-1 | PHPMailer vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:25:16.318Z
Reserved: 2020-05-27T00:00:00.000Z
Link: CVE-2020-13625
No data.
Status : Modified
Published: 2020-06-08T17:15:10.097
Modified: 2024-11-21T05:01:37.407
Link: CVE-2020-13625
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN