securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
References
Configurations
Information
Published : 2018-11-14 11:29
Updated : 2021-10-13 19:15
NVD link : CVE-2018-19277
Mitre link : CVE-2018-19277
JSON object : View
Products Affected
phpspreadsheet_project
- phpspreadsheet
CWE
CWE-91
XML Injection (aka Blind XPath Injection)
