CVE-2024-56412
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-56412 is a cross-site scripting (XSS) vulnerability affecting PhpSpreadsheet, a popular PHP library used for reading and writing spreadsheet files. The flaw, present in versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7, allows attackers to bypass the library's XSS sanitizer using the javascript protocol and special characters. By manipulating the input, an adversary can generate an HTML link containing harmful JavaScript code, posing a threat to unsuspecting users. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 of PhpSpreadsheet include a patch to address this issue, mitigating the risk of successful attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PHPOffice PhpSpreadsheet
Affected Vendors
- .php/ Office