CVE-2024-56365: PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class

Published Jan 3, 2025
·
Updated

Unauthorized Reflected XSS in the constructor of the Downloader class

Product: Phpspreadsheet Version: version 3.6.0 CWE-ID: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVSS vector v.3.1: 8.2 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N) CVSS vector v.4.0: 8.3 (AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:L/SI:H/SA:L) Description: using the /vendor/phpoffice/phpspreadsheet/samples/download.php script, an attacker can perform a XSS-type attack Impact: execution of arbitrary JavaScript code in the browser Vulnerable component: the constructor of the Downloader class Exploitation conditions: an unauthorized user Mitigation: sanitization of the name and type variables Researcher: Aleksey Solovev (Positive Technologies)

Research

The researcher discovered zero-day vulnerability Unauthorized Reflected Cross-Site Scripting (XSS) (in the constructor of the Downloader class) in Phpspreadsheet.

The latest version (3.6.0) of the phpoffice/phpspreadsheet library was installed. The installation was carried out with the inclusion of examples.

Listing 1. Installing the phpoffice/phpspreadsheet library $ composer require phpoffice/phpspreadsheet --prefer-source

The ./vendor/phpoffice/phpspreadsheet/samples/download.php file processes the GET parameters name and type.

!fig1

Figure 1. The ./vendor/phpoffice/phpspreadsheet/samples/download.php file accepts GET parameters.

Consider the constructor of the Downloader class, where GET parameters are passed. Error is displayed without sanitization using GET parameters transmitted from the user.

!fig2

Figure 2. Error is displayed without sanitization

When clicking on the following link, arbitrary JavaScript code will be executed.

Listing 2. https://192.../vendor/phpoffice/phpspreadsheet/samples/download.php?name=%3Cimg%20src=1%20onerror=alert()%3E&type=1

Demonstration of the execution of arbitrary JavaScript code.

<img width="537" alt="fig3" src="https://github.com/user-attachments/assets/745d6e21-396f-4357-8ff8-e856adf15fee" />

Figure 3. Executing arbitrary JavaScript code

Credit This vulnerability was discovered by Aleksey Solovev (Positive Technologies)

Other sources

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the Downloader class. Using the /vendor/phpoffice/phpspreadsheet/samples/download.php script, an attacker can perform a cross-site scripting attack. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.

MITRE

Affected Software

9 affected componentsFixes available
composer/phpoffice/phpexcel<=1.8.2
composer/phpoffice/phpspreadsheet>=2.2.0<=2.3.4
2.3.5
composer/phpoffice/phpspreadsheet>=2.0.0<=2.1.5
2.1.6
composer/phpoffice/phpspreadsheet<=1.29.6
1.29.7
composer/phpoffice/phpspreadsheet>=3.0.0<3.7.0
3.7.0
PHPOffice phpspreadsheet<1.29.7
PHPOffice phpspreadsheet>=2.0.0<2.1.6
PHPOffice phpspreadsheet>=2.2.0<2.3.5
PHPOffice phpspreadsheet>=3.3.0<3.7.0

Event History

Jan 3, 2025
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
DescriptionWeakness
Advisory Published
via GitHub·05:06 PM
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-56365?

CVE-2024-56365 has a CVSS score of 8.2, indicating a high severity for this vulnerability.

2

How do I fix CVE-2024-56365?

To fix CVE-2024-56365, upgrade to version 3.7.0 or later of the phpspreadsheet package.

3

What types of attacks can CVE-2024-56365 lead to?

CVE-2024-56365 can lead to unauthorized reflected Cross-Site Scripting (XSS) attacks.

4

Which versions of phpspreadsheet are affected by CVE-2024-56365?

Versions 1.29.6 and earlier, 2.2.0 to 2.3.4, and 3.0.0 to 3.6.9 of phpspreadsheet are affected by CVE-2024-56365.

5

Is CVE-2024-56365 a local or remote vulnerability?

CVE-2024-56365 is a remote vulnerability that can be exploited without local access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203