CVE-2020-13625

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmailer_project:phpmailer:*:*:*:*:*:*:*:*

Information

Published : 2020-06-08 17:15

Updated : 2020-09-17 20:15


NVD link : CVE-2020-13625

Mitre link : CVE-2020-13625


JSON object : View

Products Affected

phpmailer_project

  • phpmailer
CWE
CWE-116

Improper Encoding or Escaping of Output