PHPOffice PhpSpreadsheet
cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*
- >= 3.0.0, < 3.7.0
- <= 1.29.6
- >= 2.0.0, <= 2.1.5
- >= 2.2.0, <= 2.3.4
A reflected cross-site scripting vulnerability has been identified in PhpSpreadsheet versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7. The issue arises in the constructor of the 'Downloader' class, where user-supplied GET parameters are processed without proper sanitization. This vulnerability can be exploited by an unauthorized user through the '/vendor/phpoffice/phpspreadsheet/samples/download.php' script, leading to the execution of arbitrary JavaScript in the victim's browser.
Exploitation of this vulnerability allows for the execution of arbitrary JavaScript code in the context of the user's browser session.
To reproduce this vulnerability, upload a malicious payload to the 'name' parameter, such as an image tag with an 'onerror' event. Then, access the 'download.php' script, which will execute the JavaScript code in the browser.
Users can update to PhpSpreadsheet versions 3.7.0, 2.3.5, 2.1.6, or 1.29.7, all of which include a patch for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.