CVE-2018-19277: High severity PHPOffice phpspreadsheet vulnerability
Published Nov 14, 2018
·Updated
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
Affected Software
6 affected componentsFixes available
composer/phpoffice/phpexcel<1.8.0
composer/phpoffice/phpspreadsheet<=1.5.0
PHPOffice phpspreadsheet<=1.5.0
Phpspreadsheet Project Phpspreadsheet<=1.5.0
composer/phpoffice/phpexcel<1.8.2
1.8.2
composer/phpoffice/phpspreadsheet<1.5.1
1.5.1
Event History
Nov 14, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Nov 20, 2018
Advisory Published
07:50 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-19277?
CVE-2018-19277 is considered a medium severity vulnerability due to its potential for bypassing protection mechanisms.
2
How do I fix CVE-2018-19277?
To fix CVE-2018-19277, you should upgrade to PhpSpreadsheet version 1.5.1 or higher.
3
What does CVE-2018-19277 affect?
CVE-2018-19277 affects PhpSpreadsheet versions up to and including 1.5.0.
4
What type of vulnerability is CVE-2018-19277?
CVE-2018-19277 is an XML External Entity (XXE) vulnerability.
5
Can CVE-2018-19277 be exploited through .xlsx files?
Yes, CVE-2018-19277 can be exploited by using specially crafted .xlsx files containing UTF-7 encoded data.