Phpoffice · Phpoffice Common · CVE-2018-14065
**Name of the Vulnerable Software and Affected Versions**
PHPOffice Common versions prior to 0.2.9
**Description**
The issue allows XXE (XML External Entity) attacks. This is related to the `XMLReader.php` file in PHPOffice Common.
**Recommendations**
For versions prior to 0.2.9, update to version 0.2.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `XMLReader.php` file until a patch is applied.