CVE-2024-56408: Phpspreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
Unauthorized Reflected XSS in <code>Convert-Online.php</code> file
Product: Phpspreadsheet
Version: version 3.6.0
CWE-ID: CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
CVSS vector v.3.1: 8.2 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N)
CVSS vector v.4.0: 8.3 (AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:L/SI:H/SA:L)
Description: using the /vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php
script, an attacker can perform a XSS-type attack
Impact: executing arbitrary JavaScript code in the browser
Vulnerable component: the /vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php
file
Exploitation conditions: an unauthorized user
Mitigation: sanitization of the quantity variable
Researcher: Aleksey Solovev (Positive Technologies)
Research
The researcher discovered zero-day vulnerability Unauthorized Reflected Cross-Site Scripting (XSS) (in Convert-Online.php
file) in Phpspreadsheet.
There is no sanitization in the /vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php
file, which leads to the possibility of a XSS attack.
Figure 4. The message with the quantity parameter is displayed without sanitization
The following figure shows a POST HTTP-request and a response to the server with the variable quantity, which is displayed in the response from the server without sanitization.
Figure 5. In the server’s response , the quantity variable is displayed without sanitization
An attacker can prepare a special HTML form that will be automatically sent to the vulnerable scenario.
Listing 3. HTML form that demonstrates the exploitation of the XSS vulnerability
References
Detect and mitigate CVE-2024-56408 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →