CVE-2024-56365 | PHPOffice PhpSpreadsheet up to 1.29.6/2.1.5/2.3.4/3.6.x download.php Downloader cross site scripting (GHSA-jmpx-686v-c3wx)
A vulnerability was found in PHPOffice PhpSpreadsheet up to 1.29.6/2.1.5/2.3.4/3.6.x. It has been rated as problematic. Affected by this issue is the function Downloader of the file /vendor/phpoffice/phpspreadsheet/samples/download.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-56365. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.