High severityNVD Advisory· Published Jun 8, 2020· Updated Aug 4, 2024
CVE-2020-13625
CVE-2020-13625
Description
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
phpmailer/phpmailerPackagist | < 6.1.6 | 6.1.6 |
Affected products
12- PHPMailer/PHPMailerdescription
- osv-coords11 versionspkg:bitnami/phpmailerpkg:composer/phpmailer/phpmailerpkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1
< 6.1.6+ 10 more
- (no CPE)range: < 6.1.6
- (no CPE)range: < 6.1.6
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-bp151.4.12.1
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-bp151.4.12.1
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
15- lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.htmlghsavendor-advisoryx_refsource_SUSEWEB
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.htmlghsavendor-advisoryx_refsource_SUSEWEB
- github.com/advisories/GHSA-f7hx-fqxw-rvvjghsaADVISORY
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFM3BZABL6RUHTVMXSC7OFMP4CKWMRPJ/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMH4TC5XTS3KZVGMSKEPPBZ2XTZCKKCX/mitrevendor-advisoryx_refsource_FEDORA
- nvd.nist.gov/vuln/detail/CVE-2020-13625ghsaADVISORY
- usn.ubuntu.com/4505-1/mitrevendor-advisoryx_refsource_UBUNTU
- github.com/PHPMailer/PHPMailer/commit/c2796cb1cb99d7717290b48c4e6f32cb6c60b7b3ghsaWEB
- github.com/PHPMailer/PHPMailer/releases/tag/v6.1.6ghsax_refsource_CONFIRMWEB
- github.com/PHPMailer/PHPMailer/security/advisories/GHSA-f7hx-fqxw-rvvjghsax_refsource_CONFIRMWEB
- lists.debian.org/debian-lts-announce/2020/06/msg00014.htmlghsamailing-listx_refsource_MLISTWEB
- lists.debian.org/debian-lts-announce/2020/08/msg00004.htmlghsamailing-listx_refsource_MLISTWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFM3BZABL6RUHTVMXSC7OFMP4CKWMRPJghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SMH4TC5XTS3KZVGMSKEPPBZ2XTZCKKCXghsaWEB
- usn.ubuntu.com/4505-1ghsaWEB
News mentions
0No linked articles in our index yet.