CVE-2023-29887
Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion
Record summary
CVE-2023-29887 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHNuovo Spreadsheet Reader 0.5.11 - Local File InclusionCVSS 7.5
A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and further compromise of the server.
Remediation
Upgrade to a patched version of Nuovo Spreadsheet Reader or apply the vendor-provided fix to mitigate the Local File Inclusion vulnerability.
Source: ProjectDiscovery