Junglewise Threat Intelligence

CVE-2023-7101: Spreadsheet::ParseExcel Remote Code Execution Vulnerability

CVE-2023-7101 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-01-02

Executive brief

Spreadsheet::ParseExcel is vulnerable to remote code execution due to the evaluation of unvalidated Number format strings from Excel files within a string-type eval function. This allows an attacker to execute arbitrary Perl code when a specially crafted spreadsheet is parsed by the library.

Affected products

  • jmcnamara Spreadsheet::ParseExcel 0.65

Timeline

  • 2023-12-29: disclosed: Initial disclosure on oss-security mailing list
  • 2024-01-02: advisory: NVD publication date
  • 2024-01-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog