VYPR
High severityNVD Advisory· Published Jan 3, 2025· Updated May 20, 2025

PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file

CVE-2024-56408

Description

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the /vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php file, which leads to the possibility of a cross-site scripting attack. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
phpoffice/phpspreadsheetPackagist
>= 3.0.0, < 3.7.03.7.0
phpoffice/phpspreadsheetPackagist
< 1.29.71.29.7
phpoffice/phpspreadsheetPackagist
>= 2.0.0, < 2.1.62.1.6
phpoffice/phpspreadsheetPackagist
>= 2.2.0, < 2.3.52.3.5
phpoffice/phpexcelPackagist
<= 1.8.2

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.