VDB
Sign up
HIGH8.8

GHSA-vvwv-h69m-wg6f

XXE in PHPSpreadsheet due to incomplete fix for previous encoding issue

Quick fix

GHSA-vvwv-h69m-wg6f — phpoffice/phpspreadsheet: upgrade to the fixed version with the command below.

composer require phpoffice/phpspreadsheet:^1.8.0

Details

PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This was a security measurement to prevent CVE-2018-19277 but the fix is not sufficient. By double-encoding the the xml payload to utf-7 it is possible to bypass the check for the string ?<!ENTITY? and thus allowing for an xml external entity processing (XXE) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpoffice/phpspreadsheet
Introduced in: 0Fixed in: 1.8.0
Fixcomposer require phpoffice/phpspreadsheet:^1.8.0
Packagist/phpoffice/phpexcel
Introduced in: 0

No fixed version published yet for phpoffice/phpexcel (composer). Pin to a known-safe version or switch to an alternative.

References