Input validation error in PHPMailer - CVE-2020-13625
Published: July 6, 2020
Vulnerability identifier: #VU29531
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13625
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions
The vulnerability exists due to insufficient validation of user-supplied file attachments with a double quote character. A remote attacker can pass specially crafted filename to the application and bypass implemented security restrictions.
Affected software
PHPMailer
Cacti
cacti (Alpine package)
libphp-phpmailer (Ubuntu package)
php-PHPMailer
php-phpmailer6
SUSE Package Hub for SUSE Linux Enterprise
SUSE Linux
Opensuse
Ubuntu
Fedora
Cacti
cacti (Alpine package)
libphp-phpmailer (Ubuntu package)
php-PHPMailer
php-phpmailer6
SUSE Package Hub for SUSE Linux Enterprise
SUSE Linux
Opensuse
Ubuntu
Fedora
How to mitigate CVE-2020-13625
Install updates from vendor's website.
PHPMailer - update to 6.1.6
Cacti - update to 1.2.13
libphp-phpmailer (Ubuntu package) - addressed in versions Ubuntu Pro, 5.2.14+dfsg-2.3+deb9u2build0.18.04.1
php-PHPMailer - addressed in versions 5.2.28-2.fc31, 5.2.28-2.fc32
php-phpmailer6 - addressed in versions 6.1.6-1.fc31, 6.1.6-2.fc32
Cacti - update to 1.2.13
libphp-phpmailer (Ubuntu package) - addressed in versions Ubuntu Pro, 5.2.14+dfsg-2.3+deb9u2build0.18.04.1
php-PHPMailer - addressed in versions 5.2.28-2.fc31, 5.2.28-2.fc32
php-phpmailer6 - addressed in versions 6.1.6-1.fc31, 6.1.6-2.fc32
External References
- https://github.com/PHPMailer/PHPMailer/releases/tag/v6.1.6
- https://github.com/PHPMailer/PHPMailer/security/advisories/GHSA-f7hx-fqxw-rvvj
- https://lists.debian.org/debian-lts-announce/2020/06/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFM3BZABL6RUHTVMXSC7OFMP4CKWMRPJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SMH4TC5XTS3KZVGMSKEPPBZ2XTZCKKCX/
Related Security Bulletins
- Improper input validation in PHPMailer
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- Multiple vulnerabilities in Cacti
- OpenSUSE Linux update for cacti, cacti-spine
- Input validation error in cacti (Alpine package)
- Ubuntu update for libphp-phpmailer
- Ubuntu update for libphp-phpmailer
- Ubuntu update for libphp-phpmailer
- Fedora 31 update for php-phpmailer6
- Fedora 32 update for php-phpmailer6
- Fedora 31 update for php-PHPMailer
- Fedora 32 update for php-PHPMailer