Lucene search

K
osvGoogleOSV:USN-4505-1
HistorySep 16, 2020 - 3:25 p.m.

libphp-phpmailer vulnerability

2020-09-1615:25:17
Google
osv.dev
10
phpmailer
vulnerability
filename escape
remote attacker
cve-2020-13625

AI Score

6.7

Confidence

Low

EPSS

0.009

Percentile

82.8%

Elar Lang discovered that PHPMailer did not properly escape double quote
characters in filenames. A remote attacker could possibly exploit this
with a crafted filename to bypass attachment filters that are based on
matching filename extensions. (CVE-2020-13625)