An Pham
  • HOME
  • READ MY BLOG
  • Home
  • Cve
  • CVE 2024 23525
XXE
CVE-2024-23525
Perl Spreadsheet::ParseXLSX.
Denial of service, Open redirect
CVE-2021-22964
fastify-static.
Open redirect
CVE-2021-22963
fastify-static.

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

Reference: https://gist.github.com/phvietan/d1c95a88ab6e17047b0248d6bf9eac4a

Made by Hugo, theme by Adrián Moreno