CVE-2024-56412 | PHPOffice PhpSpreadsheet up to 1.29.6/2.1.5/2.3.4/3.6.x HTML Link HTML injection (GHSA-q9jv-mm3r-j47r)
A vulnerability classified as problematic has been found in PHPOffice PhpSpreadsheet up to 1.29.6/2.1.5/2.3.4/3.6.x. This affects an unknown part of the component HTML Link Handler. The manipulation leads to HTML injection.
This vulnerability is uniquely identified as CVE-2024-56412. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.