216.73.217.22

CVE-2025-48882

· Published 30/05/2025 20:15 · Modified 30/05/2025 20:15

Labels: CVE-2025-48882 2025-05-30CVE-2025-48882CWE-611[email protected]

Essential information

Published
30/05/2025 20:15
Modified
30/05/2025 20:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to XXE. Version 0.3.0 fixes the vulnerability.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
phpoffice / math cpe:2.3:a:phpoffice:math:<0.3.0:*:*:*:*:*:*:*

References