CVE-2020-13625: High severity phpmailer vulnerability
Last updated 24 July 2024
Other sources
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13625?
CVE-2020-13625 is a vulnerability in PHPMailer that allows for misinterpretation of file types in email attachments.
How severe is CVE-2020-13625?
CVE-2020-13625 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2020-13625?
The affected software versions include libphp-phpmailer 6.0.6-0.1 and below, 6.1.6, 6.2.0-2, and 6.6.3-1.
How can I fix CVE-2020-13625?
To fix CVE-2020-13625, update your PHPMailer installation to version 6.1.6 or higher.
Where can I find more information about CVE-2020-13625?
You can find more information about CVE-2020-13625 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html) and [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html).