Executive brief
Spreadsheet::ParseExcel is vulnerable to remote code execution due to the evaluation of unvalidated Number format strings from Excel files within a string-type eval function. This allows an attacker to execute arbitrary Perl code when a specially crafted spreadsheet is parsed by the library.
Affected products
- jmcnamara Spreadsheet::ParseExcel 0.65
Timeline
- 2023-12-29: disclosed: Initial disclosure on oss-security mailing list
- 2024-01-02: advisory: NVD publication date
- 2024-01-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog