CVE-2014-2054: XEE
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2054?
CVE-2014-2054 has a CVSS score of 5.3, indicating a medium severity vulnerability.
How do I fix CVE-2014-2054?
To fix CVE-2014-2054, you need to upgrade PHPExcel to version 1.8.0 or later.
What types of attacks can be executed through CVE-2014-2054?
CVE-2014-2054 allows remote attackers to conduct XML External Entity (XXE) attacks to read arbitrary files or cause denial of service.
Which versions of software are affected by CVE-2014-2054?
CVE-2014-2054 affects PHPExcel versions prior to 1.8.0 and ownCloud Server versions 5.0.14 and earlier as well as 6.0.x versions before 6.0.2.
What is an XML External Entity (XXE) attack in the context of CVE-2014-2054?
An XML External Entity (XXE) attack exploits the parsing of XML to read sensitive files on the server or perform other malicious actions.