CVE-2024-23525

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tozt:spreadsheet\:\:parsexlsx:*:*:*:*:*:perl:*:*

History

No history.

Information

Published : 2024-01-18 00:15

Updated : 2024-05-05 15:15


NVD link : CVE-2024-23525

Mitre link : CVE-2024-23525

CVE.ORG link : CVE-2024-23525


JSON object : View

Products Affected

tozt

  • spreadsheet\
CWE
CWE-611

Improper Restriction of XML External Entity Reference