CVE-2023-7101

Spreadsheet::ParseExcel Remote Code Execution Vulnerability

Description

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

Severity: HIGH

CVSS Score: 7.8

Vendor: Spreadsheet::ParseExcel

Product: Spreadsheet::ParseExcel

Loading CVE details...