Логотип exploitDog
bind:CVE-2024-45048
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45048

Количество 2

Количество 2

nvd логотип

CVE-2024-45048

больше 1 года назад

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This vulnerability has been addressed in release version 2.2.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-ghg6-32f9-2jp7

больше 1 года назад

XXE in PHPSpreadsheet encoding is returned

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45048

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This vulnerability has been addressed in release version 2.2.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-ghg6-32f9-2jp7

XXE in PHPSpreadsheet encoding is returned

CVSS3: 8.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу