PT-2018-12317 · Phpoffice · Phpoffice Common

Tom4T0

·

Publicado

2018-07-15

·

Atualizado

2022-05-14

·

CVE-2018-14065

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPOffice Common versions prior to 0.2.9
Description The issue allows XXE (XML External Entity) attacks. This is related to the XMLReader.php file in PHPOffice Common.
Recommendations For versions prior to 0.2.9, update to version 0.2.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the XMLReader.php file until a patch is applied.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14065
GHSA-2853-HF2G-9843

Produtos afetados

Phpoffice Common