CVE-2024-56412
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2024-56412. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the library processes the javascript protocol with special characters and generates an HTML link. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
GHSA-q9jv-mm3r-j47rAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Advisory provided by GitHub Security Advisory Database. Published: January 3, 2025, Modified: March 6, 2025