CVE-2024-23525
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
MEDIUM · CVSS 6.5
EPSS 0.00301
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0