VDB
Sign up
MEDIUM5.4

GHSA-r8w8-74ww-j4wh

PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks

Quick fix

GHSA-r8w8-74ww-j4wh — phpoffice/phpspreadsheet: upgrade to the fixed version with the command below.

composer require phpoffice/phpspreadsheet:^2.3.0

Details

### Summary `\PhpOffice\PhpSpreadsheet\Writer\Html` does not sanitize "javascript:" URLs from hyperlink `href` attributes, resulting in a Cross-Site Scripting vulnerability.

### PoC

Example target script:

``` <?php

require 'vendor/autoload.php';

$reader = \PhpOffice\PhpSpreadsheet\IOFactory::createReader("Xlsx"); $spreadsheet = $reader->load(__DIR__ . '/book.xlsx');

$writer = new \PhpOffice\PhpSpreadsheet\Writer\Html($spreadsheet); print($writer->generateHTMLAll()); ```

Save this file in the same directory: [book.xlsx](https://github.com/PHPOffice/PhpSpreadsheet/files/15099763/book.xlsx)

Open index.php in a web browser and click on both links. The first demonstrates the vulnerability in a regular hyperlink and the second in a HYPERLINK() formula.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpoffice/phpspreadsheet
Introduced in: 2.2.0Fixed in: 2.3.0
Fixcomposer require phpoffice/phpspreadsheet:^2.3.0
Packagist/phpoffice/phpspreadsheet
Introduced in: 0Fixed in: 1.29.2
Fixcomposer require phpoffice/phpspreadsheet:^1.29.2
Packagist/phpoffice/phpspreadsheet
Introduced in: 2.0.0Fixed in: 2.1.1
Fixcomposer require phpoffice/phpspreadsheet:^2.1.1
Packagist/phpoffice/phpexcel
Introduced in: 0

No fixed version published yet for phpoffice/phpexcel (composer). Pin to a known-safe version or switch to an alternative.

References