Record summary

CVE-2023-29887 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHNuovo Spreadsheet Reader 0.5.11 - Local File InclusionCVSS 7.5

A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further compromise of the server.

Remediation

Upgrade to a patched version of Nuovo Spreadsheet Reader or apply the vendor-provided fix to mitigate the Local File Inclusion vulnerability.

WeaknessesCWE-22
Authorsctflearner
Template tagscve2023cvenuovospreadsheet-readerlfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:nuovo:spreadsheet-reader:0.5.11:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2