CVE-2023-7101
HIGH KEVJmcnamara Spreadsheet < 0.65 - Code Injection
Title source: ruleDescription
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.
References (12)
Scores
CVSS v3
7.8
EPSS
0.8331
EPSS Percentile
99.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-01-02
VulnCheck KEV
2023-12-25
InTheWild.io
2024-01-02
ENISA EUVD
EUVD-2023-59285
CWE
CWE-95
CWE-94
Status
published
Products (4)
debian/debian_linux
10.0
fedoraproject/fedora
38
fedoraproject/fedora
39
jmcnamara/spreadsheet\
< 0.65
Published
Dec 24, 2023
KEV Added
Jan 02, 2024
Tracked Since
Feb 18, 2026