CVE-2020-11880

9 documents7 sources
Severity
6.5MEDIUM
EPSS
0.3%
top 49.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 17
Latest updateSep 2

Description

An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make KMail attach local files to a composed email message without showing a warning to the user, as demonstrated by an attach=.bash_history value.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages2 packages

NVDkde/kmail< 19.12.3
Debiankmail< 4:20.04.1-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-76gc-v974-87g9: An issue was discovered in KDE KMail before 192022-05-24
CVEList
CVE-2020-11880: An issue was discovered in KDE KMail before 192020-04-17
OSV
CVE-2020-11880: An issue was discovered in KDE KMail before 192020-04-17

📋Vendor Advisories

3
Ubuntu
KDE PIM vulnerabilities2025-09-02
Ubuntu
KMail vulnerabilities2025-09-02
Debian
CVE-2020-11880: kmail - An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (n...2020

💬Community

2
Bugzilla
CVE-2020-11880 kmail: using a special parameter an attacker can force kmail to attach local files to a composed email [fedora-all]2020-05-06
Bugzilla
CVE-2020-11880 kmail: using a special parameter an attacker can force kmail to attach local files to a composed email2020-05-05
CVE-2020-11880 (MEDIUM CVSS 6.5) | An issue was discovered in KDE KMai | cvebase.io