XML External Entity Processing Vulnerability in PHPOffice Math Library
CVE-2025-48882

8.7HIGH

Key Information:

Vendor

PHPoffice

Status
Vendor
CVE Published:
30 May 2025

What is CVE-2025-48882?

The PHPOffice Math library, which aids in manipulating diverse formula file formats, is susceptible to an XML External Entity (XXE) attack prior to version 0.3.0. This vulnerability arises when XML data is loaded using the standard libxml extension alongside the LIBXML_DTDLOAD flag, without adequate filtering. Attackers can exploit this flaw to potentially access sensitive data or conduct further attacks. The vulnerability has been addressed in version 0.3.0, which implements additional security measures to safeguard against such threats.

Affected Version(s)

Math < 0.3.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48882 : XML External Entity Processing Vulnerability in PHPOffice Math Library