VYPR
High severityNVD Advisory· Published Jan 3, 2025· Updated Jan 3, 2025

PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file

CVE-2024-56366

Description

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the Accounting.php file. Using the /vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Accounting.php script, an attacker can perform a cross-site scripting attack. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
phpoffice/phpspreadsheetPackagist
>= 3.0.0, < 3.7.03.7.0
phpoffice/phpspreadsheetPackagist
< 1.29.71.29.7
phpoffice/phpspreadsheetPackagist
>= 2.0.0, < 2.1.62.1.6
phpoffice/phpspreadsheetPackagist
>= 2.2.0, < 2.3.52.3.5
phpoffice/phpexcelPackagist
<= 1.8.2

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.