From 1abf061df3c95e939f88e631c1985693766ec179 Mon Sep 17 00:00:00 2001 From: Mark Baker Date: Fri, 21 Feb 2014 10:01:44 +0000 Subject: [PATCH] AS we're using simpleXML for xml reading still, we need to use libxml_disable_entity_loader(true); for XXE security patch --- Classes/PHPExcel/Settings.php | 1 + 1 file changed, 1 insertion(+) diff --git a/Classes/PHPExcel/Settings.php b/Classes/PHPExcel/Settings.php index 03e1a264..a550b55c 100644 --- a/Classes/PHPExcel/Settings.php +++ b/Classes/PHPExcel/Settings.php @@ -377,6 +377,7 @@ class PHPExcel_Settings */ public static function getLibXmlLoaderOptions() { + libxml_disable_entity_loader(true); if (is_null(self::$_libXmlLoaderOptions)) { self::$_libXmlLoaderOptions = LIBXML_DTDLOAD | LIBXML_DTDATTR; }