CVE-2018-19277

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
6.8
MEDIUM
Affected
2
PROJECTS

Description

securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

A pure PHP library for reading and writing spreadsheet files
GitHubGitHub
13.9K
This Symfony bundle integrates PhpSpreadsheet into Symfony using Twig.
GitHubGitHub
22