ZeroHour

CVE-2020-13625

PoC
CVSS 3.1
7.5 high
EPSS
4%p89
Published
()
Modified
Description

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

Vendors
phpmailer projectfedoraprojectcanonicaldebian
Products
phpmailer, fedora, ubuntu linux, debian linux
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.