CVE-2024-45291
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-45291 is a serious vulnerability affecting the PHPSpreadsheet library. Maliciously crafted XLSX files can trick the software into embedding images from unintended paths, leading to Server-Side Request Forgery (SSRF). If image embedding has been enabled, an attacker can read arbitrary files on the server and execute arbitrary HTTP GET requests. The vulnerability is particularly dangerous because it can be exploited even with non-image file types. PHP protocol wrappers can exacerbate the issue, potentially enabling remote code execution. Release versions 1.29.2, 2.1.1, and 2.3.0 contain the necessary fixes. Users are strongly advised to upgrade as soon as possible, as there are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PHPOffice PhpSpreadsheet
Affected Vendors
- .php/ Office