PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2244-1 | libphp-phpmailer security update |
![]() |
DLA-2306-1 | libphp-phpmailer security update |
![]() |
EUVD-2020-0422 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message. |
![]() |
GHSA-f7hx-fqxw-rvvj | Insufficient output escaping of attachment names in PHPMailer |
![]() |
USN-4505-1 | PHPMailer vulnerability |
![]() |
USN-5956-1 | PHPMailer vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:25:16.318Z
Reserved: 2020-05-27T00:00:00
Link: CVE-2020-13625

No data.

Status : Modified
Published: 2020-06-08T17:15:10.097
Modified: 2024-11-21T05:01:37.407
Link: CVE-2020-13625

No data.

No data.