CVE-2024-56412

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 3, 2025
Updated: Mar 6, 2025
CWE ID 79

Summary

CVE-2024-56412 is a cross-site scripting (XSS) vulnerability affecting PhpSpreadsheet, a popular PHP library used for reading and writing spreadsheet files. The flaw, present in versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7, allows attackers to bypass the library's XSS sanitizer using the javascript protocol and special characters. By manipulating the input, an adversary can generate an HTML link containing harmful JavaScript code, posing a threat to unsuspecting users. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 of PhpSpreadsheet include a patch to address this issue, mitigating the risk of successful attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PHPOffice PhpSpreadsheet

Affected Vendors

  • .php/ Office