CVE Database
/

CVE-2023-7101

Back to search

CVE-2023-7101

Published: Dec 24, 2023

Modified: Oct 21, 2025

PUBLISHED

Description

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic.

VendorProductVersions

Douglas Wilson

Spreadsheet::ParseExcel

affected
0.65

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now