CVE-2024-45060

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 17, 2024
CWE ID 79

Summary

CVE-2024-45060 is a cross-site scripting (XSS) vulnerability affecting PHPSpreadsheet, a popular PHP library for handling spreadsheet files. The issue stems from a sample script, specifically `45_Quadratic_equation_solver.php`, which concatenates user-supplied parameters into spreadsheet formulas without proper validation. An attacker can manipulate these formulas to inject malicious JavaScript code, leading to unintended output and potential code execution. This vulnerability has been addressed in releases 1.29.2, 2.1.1, and 2.3.0, and users are urged to upgrade as soon as possible. Currently, there are no known workarounds for this flaw.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PHPOffice PhpSpreadsheet

Affected Vendors

  • .php/ Office