PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input
- С сайта: Vulnerability(cybersecuritynews.com)
- Вернуться к списку новостей
PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input
Author: Florence NightingaleA high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security.
The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice/phpspreadsheet package and carries a CVSS v4.0 score of 8.7.
Key Takeaways
1. SSRF in PhpSpreadsheet’s Worksheet\Drawing::setPath via malicious HTML image tags.
2. Affects < 1.30.0, 2.0.0–2.1.11, 2.2.0–2.3.x, 3.0.0–3.9.x, 4.x
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news #vulnerability
Оригинальная версия на сайте:


