CVE-2018-19277
HIGH8.8EPSS 3.0%XXE in PHPSpreadsheet due to encoding issue
發布日:2019/11/20修改日:2025/3/6
描述
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
受影響套件(2)
- Packagist/phpoffice/phpexcelfrom 0, < 1.8.2
- Packagist/phpoffice/phpspreadsheetfrom 0, < 1.5.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(12)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-19277
- PATCHhttps://github.com/PHPOffice/PhpSpreadsheet
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/phpoffice/phpspreadsheet/CVE-2018-19277.yaml
- WEBhttps://github.com/MewesK/TwigSpreadsheetBundle/issues/18
- WEBhttps://github.com/PHPOffice/PHPExcel/commit/2b601574975acfb9d4378a788ed5f2b747958095
- WEBhttps://github.com/PHPOffice/PHPExcel/commits/1.8.2
- WEBhttps://github.com/PHPOffice/PhpSpreadsheet/commit/0f8f071e24ee8b114d894ac172f77dc250e5bfa4
- WEBhttps://github.com/PHPOffice/PhpSpreadsheet/issues/771
- WEBhttps://github.com/PHPOffice/PhpSpreadsheet/pull/780
- WEBhttps://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.5.1
- WEBhttps://www.bishopfox.com/news/2018/11/phpoffice-versions
- WEBhttps://www.drupal.org/sa-contrib-2021-043