Skip to content

PHPExcel vulnerable to XXE attacks through libxml

Moderate severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Sep 25, 2023

Package

composer phpoffice/phpexcel (Composer)

Affected versions

< 1.8.0

Patched versions

1.8.0

Description

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

References

Published by the National Vulnerability Database Jun 4, 2014
Published to the GitHub Advisory Database May 17, 2022
Reviewed Sep 25, 2023
Last updated Sep 25, 2023

Severity

Moderate

EPSS score

0.527%
(78th percentile)

Weaknesses

CVE ID

CVE-2014-2054

GHSA ID

GHSA-28rm-rj57-qjpv

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.