CVE-2024-56409
CVE-2024-56409: Cross-site scripting (XSS) vulnerability in PhpSpreadsheet's Currency.php. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users. The PhpSpreadsheet library, versions before 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are affected, potentially leading to unauthorized script execution when users interact with the /vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Currency.php
script. While the CVSS score is 0, indicating no impact according to that scoring system, the SOCRadar Vulnerability Risk Score (SVRS) is 30. An SVRS of 30 suggests that while not critical, this vulnerability presents a real risk. Upgrade to version 3.7.0, 2.3.5, 2.1.6, or 1.29.7 to mitigate the security risk. This CVE is significant due to the widespread use of PhpSpreadsheet in web applications, potentially exposing many systems to XSS attacks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.