logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-56412

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-56412

Description:
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the library processes the javascript protocol with special characters and generates an HTML link. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.
Last updated date:
03/06/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/06/2025
Reference url to background

https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-q9jv-mm3r-j47r

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy