Description
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1943 | PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. |
Github GHSA |
GHSA-28rm-rj57-qjpv | PHPExcel vulnerable to XXE attacks through libxml |
References
History
Mon, 31 Mar 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owncloud owncloud Server
|
|
| CPEs | cpe:2.3:a:owncloud:owncloud:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.10:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.11:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.12:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.13:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.14:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.7:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.8:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.9:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:6.0.1:*:*:*:*:*:*:* |
cpe:2.3:a:owncloud:owncloud_server:*:a:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.10:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.11:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.12:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.13:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.14:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.7:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.8:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.9:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:6.0.1:*:*:*:*:*:*:* |
| Vendors & Products |
Owncloud owncloud
|
Owncloud owncloud Server
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T09:58:16.333Z
Reserved: 2014-02-19T00:00:00.000Z
Link: CVE-2014-2054
No data.
Status : Deferred
Published: 2014-06-04T14:55:03.983
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2054
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA