CVE-2024-45060
Last modified
CVE-2024-45060 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of input where a number is expected leading to formula injection. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of input where a number is expected leading to formula injection. The code in in `45_Quadratic_equation_solver.php` concatenates the user supplied parameters directly into spreadsheet formulas. This allows an attacker to take control over the formula and output unsanitized data into the page, resulting in JavaScript execution. This issue has been addressed in release versions 1.29.2, 2.1.1, and 2.3.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpoffice | Phpspreadsheet | < 1.29.2 |
| Phpoffice | Phpspreadsheet | >= 2.0.0, < 2.1.1 |
| Phpoffice | Phpspreadsheet | >= 2.2.0, < 2.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45060?
How severe is CVE-2024-45060?
How do I fix CVE-2024-45060?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45054Hwameistor is an HA local storage system for cloud-native st…6.7
- CVE-2024-45056zksolc is a Solidity compiler for ZKsync. All LLVM versions …5.9
- CVE-2024-45057i-Educar is free, fully online school management software th…6.1
- CVE-2024-45058i-Educar is free, fully online school management software th…8.1
- CVE-2024-45059i-Educar is free, fully online school management software th…8.8
- CVE-2024-4506A vulnerability has been found in Ruijie RG-UAC up to 202404…7.2
- CVE-2024-45061A cross-site scripting (xss) vulnerability exists in the wea…5.4
- CVE-2024-45062A stack based buffer overflow vulnerability is present in Op…6.8
- CVE-2024-45063The function ctl_write_buffer incorrectly set a flag which r…8.8
- CVE-2024-45064A buffer overflow vulnerability exists in the FileX Internal…9.8
- CVE-2024-45065Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2024-45066A specially crafted POST request to the ProGauge MAGLINK LX …9.8
Are you affected by CVE-2024-45060?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
