PT-2018-14898 · Phpoffice · Phpoffice Phpspreadsheet

CVE-2018-19277

·

Publicado

2018-11-14

·

Atualizado

2024-09-04

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPOffice PhpSpreadsheet versions prior to 1.5.1
Description The issue allows a bypass of protection mechanisms for XML External Entity (XXE) attacks via UTF-7 encoding in a .xlsx file. This is achieved through the securityScan() function in PHPOffice PhpSpreadsheet.
Recommendations For PHPOffice PhpSpreadsheet versions prior to 1.5.1, update to version 1.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the securityScan() function until a patch is available. Restrict access to .xlsx files to minimize the risk of exploitation. Avoid using UTF-7 encoding in .xlsx files until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19277
GHSA-XCRG-29H7-H4CJ

Produtos afetados

Phpoffice Phpspreadsheet