cvedb.io
CVE-2024-56412
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2025-01-03T18:15:16.380 · Last modified 2026-06-17T08:12:09.637

Summary

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the library processes the javascript protocol with special characters and generates an HTML link. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.

Affected products

phpoffice — phpspreadsheet

Does this affect you?

Add your gear to cvedb and we'll alert you only when phpoffice ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.