PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
No PoCs from references.
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon
- https://github.com/KatenKyoukotsu/devsecops
- https://github.com/Live-Hack-CVE/CVE-2020-13625
- https://github.com/cyb3r-w0lf/nuclei-template-collection