CVE-2024-23525: Tozt Spreadsheet::parsexlsx
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
Affected products
- Tozt Spreadsheet::parsexlsx: before 0.30 (fixed in 0.30)
Published 2024-01-18. Last modified 2026-06-17.