SB2020070602 - Improper input validation in PHPMailer
Published: July 6, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-13625)
The vulnerability allows a remote attacker to bypass implemented security restrictions
The vulnerability exists due to insufficient validation of user-supplied file attachments with a double quote character. A remote attacker can pass specially crafted filename to the application and bypass implemented security restrictions.
Remediation
Install update from vendor's website.
References
- https://github.com/PHPMailer/PHPMailer/releases/tag/v6.1.6
- https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-f7hx-fqxw-rvvj
- https://lists.debian.org/debian-lts-announce/2020/06/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFM3BZABL6RUHTVMXSC7OFMP4CKWMRPJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SMH4TC5XTS3KZVGMSKEPPBZ2XTZCKKCX/