OS Command Injection In libphp-phpmailer
Description
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 6.1.6-1 | ||
debian 12 | 6.1.6-1 | ||
packagist | 6.1.6 | ||
debian 11 | 6.1.6-1 | ||
debian 14 | 6.1.6-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6. 7. 8.