securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| phpoffice/phpspreadsheet(Packagist) | 0 | 1.5.1 | N/A |
| phpoffice/phpexcel(Packagist) | 0 | 1.8.2 | N/A |
CVSS Metrics