Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0039 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the library processes the javascript protocol with special characters and generates an HTML link. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue. |
Github GHSA |
GHSA-q9jv-mm3r-j47r | PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 06 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpoffice
Phpoffice phpspreadsheet |
|
| CPEs | cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phpoffice
Phpoffice phpspreadsheet |
|
| Metrics |
cvssV3_1
|
Fri, 03 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 03 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the library processes the javascript protocol with special characters and generates an HTML link. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue. | |
| Title | PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special characters | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-03T17:35:43.196Z
Reserved: 2024-12-23T15:07:48.510Z
Link: CVE-2024-56412
Updated: 2025-01-03T17:35:37.320Z
Status : Analyzed
Published: 2025-01-03T18:15:16.380
Modified: 2025-03-06T13:30:34.893
Link: CVE-2024-56412
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA