PT-2025-4368 · Unknown · Phpspreadsheet

Trikkss

·

Published

2024-12-23

·

Updated

2025-10-27

·

CVE-2025-22131

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PhpSpreadsheet (affected versions not specified)
Description The issue is related to a Cross-Site Scripting (XSS) vulnerability in the code that translates XLSX files into HTML representations and displays them in the response. This occurs when generating HTML from an XLSX file containing multiple sheets, where the sheet names are not sanitized, allowing an attacker to execute JavaScript code. The impact of this vulnerability can range from annoyance to complete account compromise, including disclosure of user session cookies, redirecting users to other pages, modifying content, automatically downloading malicious files, and requesting access to victim geolocation or camera.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-01639
CVE-2025-22131
GHSA-79XX-VF93-P7CX

Affected Products

Phpspreadsheet