S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-29887 Scanner

Detects 'Local File Inclusion' vulnerability in spreadsheet-reader affects v. 0.5.11.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-29887
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the File parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Spreadsheet-reader is a library used to read spreadsheet files in PHP. It is an open-source project that enables developers to work with various file formats, such as Excel, LibreOffice Calc, and Google Sheets. This library allows for easy parsing and reading of spreadsheets by converting them into tabular data that can be imported into other applications or used within PHP scripts. The spreadsheet-reader also provides support for various data types and formulas, which makes it a valuable tool for developers who work with data.

However, a serious vulnerability was detected in the spreadsheet-reader version 0.5.11. The CVE-2023-29887 vulnerability allows remote attackers to include arbitrary files via the File parameter in the test.php file. This vulnerability can be exploited by attackers to access sensitive data, execute malicious code, or compromise the entire system.

When exploited, this vulnerability can lead to significant damages. Attackers can use the spreadsheet-reader to execute arbitrary code on the server, which can ultimately result in unauthorized access to confidential data. For example, they can insert malware that steals user credentials, installs ransomware, or even deletes critical files. This vulnerability can also result in denial-of-service attacks, which can render the system unresponsive or unusable.

In conclusion, the spreadsheet-reader is a valuable tool for developers working with spreadsheets. However, the CVE-2023-29887 vulnerability presents a serious risk to any system that uses this library. By taking the necessary precautions outlined above, users can protect their digital assets from this vulnerability. Users can also benefit from the pro features of the s4e.io platform, which provides quick and easy access to valuable information about vulnerabilities in their digital assets. By staying informed and taking proactive measures, users can stay one step ahead of potential attackers.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Upgrade spreadsheet-reader to the latest version to ensure that it is not affected by this vulnerability.
  • Review and monitor web application logs regularly to detect any suspicious activity.
  • Implement robust access control mechanisms to prevent unauthorized access to sensitive data.
  • Use firewalls and intrusion prevention systems to detect and block malicious traffic to the server.
  • Conduct regular vulnerability audits and penetration testing to identify and address any security weaknesses before attackers exploit them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.