Security Advisories (1)
CVE-2024-23525 (2024-01-17)

In default configuration of Spreadsheet::ParseXLSX, whenever we call Spreadsheet::ParseXLSX->new()->parse('user_input_file.xlsx'), we'd be vulnerable for XXE vulnerability if the XLSX file that we are parsing is from user input.

Changes for version 0.28 - 2024-01-02

  • New maintainer
  • Fix possible memory bomb as reported in https://github.com/haile01/perl_spreadsheet_excel_rce_poc/blob/main/parse_xlsx_bomb.md
  • Updated Dist::Zilla configuration fixing deprecation warnings

Documentation

Modules

parse XLSX files
helper class to open password protected files
decryptor for files of version 4.4