The Spreadsheet::ParseXLSX package before 0.30 for Perl...
Moderate severity
Unreviewed
Published
Jan 18, 2024
to the GitHub Advisory Database
•
Updated May 5, 2024
Description
Published by the National Vulnerability Database
Jan 18, 2024
Published to the GitHub Advisory Database
Jan 18, 2024
Last updated
May 5, 2024
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
References