← Browse

CVE-2023-7101

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
19.1%
97.2th percentile
CISA KEV
Listed
Added 2024-01-02 · patch by 2024-01-23
Weakness / dates
Published — · modified —

Timeline

Description

Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings within the Excel parsing logic.

Official: NVD · CVE.org