The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for phpoffice/phpexcel
.
Affected versions of this package are vulnerable to XML External Entity. The XmlScanner decodes the sheet1.xml
from an .xlsx
to UTF-8
if something else than UTF-8
is declared in the header. This was a security measurement to prevent CVE-2018-19277 but the fix is not sufficient. By double-encoding the the XML payload to UTF-7
it is possible to bypass the check for the string <!ENTITY
.