CVE-2020-13625 PUBLISHED

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

EPSS 4.55% · 89.1th percentile

Risk Scores

EPSS Score
4.55%
89.1th percentile

Affected Products

VendorProductVersions
Bitnamiphpmailer0
Bitnamiphpmailer0

Timeline

References

Open in Interactive Console →