CVE-2024-23525
Published Jan 18, 2024The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
Vendor archive
2 CVEs tagged to vendor tozt — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize impleme…