PT-2018-12317 · Phpoffice · Phpoffice Common

Tom4T0

·

Published

2018-07-15

·

Updated

2022-05-14

·

CVE-2018-14065

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPOffice Common versions prior to 0.2.9
Description The issue allows XXE (XML External Entity) attacks. This is related to the XMLReader.php file in PHPOffice Common.
Recommendations For versions prior to 0.2.9, update to version 0.2.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the XMLReader.php file until a patch is applied.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14065
GHSA-2853-HF2G-9843

Affected Products

Phpoffice Common