CVE-2022-23640 is a critical XML External Entity (XXE) vulnerability (CWE-611, CWE-776) affecting Excel-Streaming-Reader versions prior to 2.1.0. This flaw stems from insufficient XML parser settings, allowing attackers to potentially read arbitrary files, execute arbitrary code, or perform denial-of-service attacks. With a CVSS score of 9.8 (CRITICAL), it presents a high risk due to its network-based attack vector, low attack complexity, and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploits, or Metasploit/Nuclei modules are currently known, and community discussion is minimal, immediate patching to version 2.1.0 is crucial as there is no workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.0CPE matchmatch criteria | cpe:2.3:a:excel_streaming_reader_project:excel_streaming_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.