Later archive addition
PhpSpreadsheet Versions <= 1.5.0 — XXE injection
The advisory describes XML external entity injection in PhpSpreadsheet when parsing attacker-supplied spreadsheet formats. Crafted workbook XML can cause server-side file reads or outbound requests, exposing local data and network resources in applications that treat uploaded spreadsheets as safe documents.
Record
- Researcher
- @bishopfox
- Published by
- Bishop Fox
- Format
- Advisory
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @bishopfox, first published at the original source. Preserved copies are kept so the citation survives its host.