High severity7.5NVD Advisory· Published Jun 8, 2020· Updated Jun 17, 2026
CVE-2020-13625
CVE-2020-13625
Description
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
phpmailer/phpmailerPackagist | < 6.1.6 | 6.1.6 |
Affected products
18- osv-coords11 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:composer/phpmailer/phpmailerpkg:bitnami/phpmailerpkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.2
< 1.2.18-1.2+ 10 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 6.1.6
- (no CPE)range: < 6.1.6
- (no CPE)range: < 1.2.13-bp151.4.12.1
- (no CPE)range: < 1.2.13-bp151.4.12.1
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-8.1
- (no CPE)range: < 1.2.13-11.1
- (no CPE)range: < 1.2.13-8.1
- PHPMailer/PHPMailerdescription
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Patches
Vulnerability mechanics
References
15- github.com/PHPMailer/PHPMailer/security/advisories/GHSA-f7hx-fqxw-rvvjnvdExploitPatchThird Party AdvisoryWEB
- github.com/PHPMailer/PHPMailer/releases/tag/v6.1.6nvdRelease NotesThird Party AdvisoryWEB
- github.com/advisories/GHSA-f7hx-fqxw-rvvjghsaADVISORY
- lists.debian.org/debian-lts-announce/2020/06/msg00014.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/08/msg00004.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-13625ghsaADVISORY
- usn.ubuntu.com/4505-1/nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.htmlnvdBroken LinkWEB
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.htmlnvdBroken LinkWEB
- github.com/PHPMailer/PHPMailer/commit/c2796cb1cb99d7717290b48c4e6f32cb6c60b7b3ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/EFM3BZABL6RUHTVMXSC7OFMP4CKWMRPJghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/SMH4TC5XTS3KZVGMSKEPPBZ2XTZCKKCXghsaWEB
- usn.ubuntu.com/4505-1ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFM3BZABL6RUHTVMXSC7OFMP4CKWMRPJ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMH4TC5XTS3KZVGMSKEPPBZ2XTZCKKCX/nvd
News mentions
0No linked articles in our index yet.