What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.
Explanation of Vulnerability in Simple Terms
02Summary
SpreadsheetConverter's Import Spreadsheets from Microsoft Excel allows authenticated administrators to upload files without proper validation. An attacker with high-level site access can upload malicious files that affect confidentiality, integrity, and availability across the site. Update to a version newer than 10.1.4.
What an attacker can do
03Attacker Capabilities
Upload malicious files to compromise site confidentiality, integrity, and availability.
Potential impact on your site
04Site Impact
A compromised admin account can upload files that damage or expose your entire site.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrator privileges on the site.
Key dates
06Disclosure timeline
July 12, 2024
CVE published
April 28, 2026
Record updated