CVE-2024-56365: PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class
Unauthorized Reflected XSS in the constructor of the Downloader class
Product: Phpspreadsheet Version: version 3.6.0 CWE-ID: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVSS vector v.3.1: 8.2 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N) CVSS vector v.4.0: 8.3 (AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:L/SI:H/SA:L) Description: using the /vendor/phpoffice/phpspreadsheet/samples/download.php script, an attacker can perform a XSS-type attack Impact: execution of arbitrary JavaScript code in the browser Vulnerable component: the constructor of the Downloader class Exploitation conditions: an unauthorized user Mitigation: sanitization of the name and type variables Researcher: Aleksey Solovev (Positive Technologies)
Research
The researcher discovered zero-day vulnerability Unauthorized Reflected Cross-Site Scripting (XSS) (in the constructor of the Downloader class) in Phpspreadsheet.
The latest version (3.6.0) of the phpoffice/phpspreadsheet library was installed. The installation was carried out with the inclusion of examples.
Listing 1. Installing the phpoffice/phpspreadsheet library $ composer require phpoffice/phpspreadsheet --prefer-source
The ./vendor/phpoffice/phpspreadsheet/samples/download.php file processes the GET parameters name and type.
!fig1
Figure 1. The ./vendor/phpoffice/phpspreadsheet/samples/download.php file accepts GET parameters.
Consider the constructor of the Downloader class, where GET parameters are passed. Error is displayed without sanitization using GET parameters transmitted from the user.
!fig2
Figure 2. Error is displayed without sanitization
When clicking on the following link, arbitrary JavaScript code will be executed.
Listing 2. https://192.../vendor/phpoffice/phpspreadsheet/samples/download.php?name=%3Cimg%20src=1%20onerror=alert()%3E&type=1
Demonstration of the execution of arbitrary JavaScript code.
<img width="537" alt="fig3" src="https://github.com/user-attachments/assets/745d6e21-396f-4357-8ff8-e856adf15fee" />
Figure 3. Executing arbitrary JavaScript code
Credit This vulnerability was discovered by Aleksey Solovev (Positive Technologies)
Other sources
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the Downloader class. Using the /vendor/phpoffice/phpspreadsheet/samples/download.php script, an attacker can perform a cross-site scripting attack. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56365?
CVE-2024-56365 has a CVSS score of 8.2, indicating a high severity for this vulnerability.
How do I fix CVE-2024-56365?
To fix CVE-2024-56365, upgrade to version 3.7.0 or later of the phpspreadsheet package.
What types of attacks can CVE-2024-56365 lead to?
CVE-2024-56365 can lead to unauthorized reflected Cross-Site Scripting (XSS) attacks.
Which versions of phpspreadsheet are affected by CVE-2024-56365?
Versions 1.29.6 and earlier, 2.2.0 to 2.3.4, and 3.0.0 to 3.6.9 of phpspreadsheet are affected by CVE-2024-56365.
Is CVE-2024-56365 a local or remote vulnerability?
CVE-2024-56365 is a remote vulnerability that can be exploited without local access.