CVE-2024-45291

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 16, 2024
CWE ID 918
CWE ID 22
CWE ID 36

Summary

CVE-2024-45291 is a serious vulnerability affecting the PHPSpreadsheet library. Maliciously crafted XLSX files can trick the software into embedding images from unintended paths, leading to Server-Side Request Forgery (SSRF). If image embedding has been enabled, an attacker can read arbitrary files on the server and execute arbitrary HTTP GET requests. The vulnerability is particularly dangerous because it can be exploited even with non-image file types. PHP protocol wrappers can exacerbate the issue, potentially enabling remote code execution. Release versions 1.29.2, 2.1.1, and 2.3.0 contain the necessary fixes. Users are strongly advised to upgrade as soon as possible, as there are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PHPOffice PhpSpreadsheet

Affected Vendors

  • .php/ Office