Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21930
HistoryNov 08, 2019 - 3:24 a.m.

XML External Entity (XXE)

2019-11-0803:24:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.02

Percentile

88.8%

PHPOffice PhpSpreadsheet is vulnerable to XXE. The fix to prevent CVE-2018-19277 was not sufficient to protect against the previous vulnerability. An attacker is able to bypass the mitigation by double-encoding the the XML payload into utf-7 and bypass the check for the string ?<!ENTITY?.