VYPR
Moderate severityNVD Advisory· Published Jan 20, 2025· Updated Jan 21, 2025

Cross-Site Scripting (XSS) vulnerability in generateNavigation() function

CVE-2025-22131

Description

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
phpoffice/phpspreadsheetPackagist
>= 3.0.0, < 3.8.03.8.0
phpoffice/phpspreadsheetPackagist
< 1.29.81.29.8
phpoffice/phpspreadsheetPackagist
>= 2.0.0, < 2.1.72.1.7
phpoffice/phpspreadsheetPackagist
>= 2.2.0, < 2.3.62.3.6
phpoffice/phpexcelPackagist
<= 1.8.2

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.