XML External Entity Processing Vulnerability in PHPOffice Math Library
CVE-2025-48882
8.7HIGH
What is CVE-2025-48882?
The PHPOffice Math library, which aids in manipulating diverse formula file formats, is susceptible to an XML External Entity (XXE) attack prior to version 0.3.0. This vulnerability arises when XML data is loaded using the standard libxml extension alongside the LIBXML_DTDLOAD flag, without adequate filtering. Attackers can exploit this flaw to potentially access sensitive data or conduct further attacks. The vulnerability has been addressed in version 0.3.0, which implements additional security measures to safeguard against such threats.
Affected Version(s)
Math < 0.3.0