Web Hack List

Later archive addition

PhpSpreadsheet Versions <= 1.5.0 — XXE injection

The advisory describes XML external entity injection in PhpSpreadsheet when parsing attacker-supplied spreadsheet formats. Crafted workbook XML can cause server-side file reads or outbound requests, exposing local data and network resources in applications that treat uploaded spreadsheets as safe documents.

Record

Researcher
@bishopfox
Published by
Bishop Fox
Format
Advisory

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @bishopfox, first published at the original source. Preserved copies are kept so the citation survives its host.