Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2018-19277] PhpSpreadsheet Versions<=1.5.0 - XXE injection

bishopfox.com | vulnerability | CVE-2018-19277 | #php | #vulnerability | #xxe | #phpspreadsheet | #cve-2018-19277 | #file-read

Summary

PhpSpreadsheet up to 1.5.0 is vulnerable to XXE (CVE-2018-19277): attackers bypass its entity check with a UTF-7 encoded XLSX payload to read files, secrets and source code.
Published
Collected

original ↗

Related coverage

back