securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
References
Link | Resource |
---|---|
https://github.com/PHPOffice/PhpSpreadsheet/issues/771 | Exploit Third Party Advisory |
https://www.bishopfox.com/news/2018/11/phpoffice-versions/ | Broken Link |
https://github.com/MewesK/TwigSpreadsheetBundle/issues/18 | Third Party Advisory |
https://www.drupal.org/sa-contrib-2021-043 | Third Party Advisory |
Configurations
Information
Published : 2018-11-14 03:29
Updated : 2022-04-18 10:32
NVD link : CVE-2018-19277
Mitre link : CVE-2018-19277
JSON object : View
CWE
CWE-91
XML Injection (aka Blind XPath Injection)
Products Affected
phpspreadsheet_project
- phpspreadsheet