Lucene search

K
osvGoogleOSV:GHSA-28RM-RJ57-QJPV
HistoryMay 17, 2022 - 4:42 a.m.

PHPExcel vulnerable to XXE attacks through libxml

2022-05-1704:42:46
Google
osv.dev
6
phpexcel
vulnerability
xxe
libxml
owncloud
server
remote attackers

AI Score

7.6

Confidence

High

EPSS

0.005

Percentile

77.0%

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

AI Score

7.6

Confidence

High

EPSS

0.005

Percentile

77.0%