CVE-2018-14065: XEE
Published Jul 15, 2018
·Updated
XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.
Other sources
XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.
Affected Software
2 affected componentsFixes available
composer/phpoffice/common<0.2.9
0.2.9
Phpoffice Project Common<0.2.9
Event History
Jul 15, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-14065?
CVE-2018-14065 has a medium severity rating due to the potential for XML External Entity (XXE) attacks.
2
How do I fix CVE-2018-14065?
To fix CVE-2018-14065, upgrade PHPOffice Common to version 0.2.9 or later.
3
What software versions are affected by CVE-2018-14065?
CVE-2018-14065 affects versions of PHPOffice Common prior to 0.2.9.
4
What type of vulnerability is CVE-2018-14065?
CVE-2018-14065 is classified as an XML External Entity (XXE) vulnerability.
5
What impact could CVE-2018-14065 have on my application?
CVE-2018-14065 could allow an attacker to expose sensitive files or perform other malicious actions through crafted XML input.