Description
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1943 | PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. |
Github GHSA |
GHSA-28rm-rj57-qjpv | PHPExcel vulnerable to XXE attacks through libxml |
References
History
Mon, 31 Mar 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owncloud owncloud Server
|
|
| CPEs | cpe:2.3:a:owncloud:owncloud:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.10:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.11:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.12:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.13:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.14:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.7:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.8:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:5.0.9:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud:6.0.1:*:*:*:*:*:*:* |
cpe:2.3:a:owncloud:owncloud_server:*:a:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.10:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.11:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.12:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.13:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.14:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.1:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.2:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.3:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.4:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.6:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.7:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.8:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:5.0.9:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:6.0.0:*:*:*:*:*:*:* cpe:2.3:a:owncloud:owncloud_server:6.0.1:*:*:*:*:*:*:* |
| Vendors & Products |
Owncloud owncloud
|
Owncloud owncloud Server
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T09:58:16.333Z
Reserved: 2014-02-19T00:00:00.000Z
Link: CVE-2014-2054
No data.
Status : Modified
Published: 2014-06-04T14:55:03.983
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-2054
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA