CVE-2024-45048·PHP vulnerability
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This vulnerability has been addressed in release version 2.2.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.
- Severity
- high
- Software
- PHP
- Fixed in
- 2.2.1
- Published
- 2024-08-28
Affected versions
From: 2.0.0
Until: 2.2.1
Fixed in: 2.2.1
How to fix this CVE
Update PHPSpreadsheet to version 2.2.1 or later to patch the XXE filter bypass vulnerability. Organizations using PHP applications that depend on PHPSpreadsheet library versions 2.0.0 through 2.2.0 should prioritize this update to prevent attackers from reading sensitive local files through malicious spreadsheet uploads. Ensure composer dependencies are refreshed after the upgrade.
sudo dnf update php php-cli php-common -y && composer update phpoffice/phpspreadsheetDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST request to spreadsheet upload endpoint with XML payload containing DOCTYPE declaration with SYSTEM entity reference: regex pattern (?i)(<!DOCTYPE|<!ENTITY|SYSTEM|file://)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement input validation rules to reject uploaded spreadsheet files containing XML declarations or DOCTYPE declarations. Block multipart POST requests with Content-Type application/vnd.openxmlformats-officedocument.spreadsheetml.sheet or application/xml containing entity references before reaching the PHP application handler.How to check if you are affected
- Check installed PHPSpreadsheet version: composer show phpoffice/phpspreadsheet | grep versions
- Locate spreadsheet file processing endpoints: grep -r 'PHPSpreadsheet\|IOFactory' /var/www --include='*.php' | head -20
- Search application logs for XML parsing errors or file access attempts: grep -i 'xml\|XXE\|entity' /var/log/apache2/error.log /var/log/php-fpm.log 2>/dev/null | tail -50
- Verify the fix: composer show phpoffice/phpspreadsheet | grep -E 'version|2\.2\.[1-9]'
FAQ
What is CVE-2024-45048?
CVE-2024-45048 is an XML External Entity (XXE) vulnerability in PHPSpreadsheet that allows attackers to bypass security filters and read arbitrary local files from the server by uploading specially crafted spreadsheet files. The vulnerability persists even when PHP error reporting is disabled, making it difficult to detect.
Is CVE-2024-45048 being actively exploited?
No, CVE-2024-45048 is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are available at this time. However, the vulnerability is high-severity and should be remediated promptly as proof-of-concept code could emerge.
What versions of PHP are affected by CVE-2024-45048?
This vulnerability affects PHPSpreadsheet library versions 2.0.0 through 2.2.0 inclusive. Version 2.2.1 and later contain the necessary filter improvements to prevent XXE attacks.
How do I check if my server is vulnerable to CVE-2024-45048?
Run 'composer show phpoffice/phpspreadsheet' to retrieve the installed version. If the version falls between 2.0.0 and 2.2.0, your system is vulnerable and requires immediate update to 2.2.1 or later.
Does Defensia detect CVE-2024-45048?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHPSpreadsheet is installed on a monitored server, CVE-2024-45048 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-45048. Free for 1 server.
Get started free