claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2023-7101-spreadsheetparseexcel-spreadsheetparseexcel.log

CVE-2023-7101 — Spreadsheet::ParseExcel Remote Code Execution Vulnerability

2024-01-02 • CISA Known Exploited Vulnerability


[event] Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

> AFFECTED SOFTWARE

Field Value
Vendor Spreadsheet::ParseExcel
Product Spreadsheet::ParseExcel
CWE CWE-95
CVE ID CVE-2023-7101
Date Added 2024-01-02
Due Date 2024-01-23
Ransomware Campaign Unknown

> MITIGATION

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 2024-01-23

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:10 UTC