PT-2018-13584 · Exceljs · Exceljs

Bl4De

+1

·

Published

2018-09-06

·

Updated

2019-10-09

·

CVE-2018-16459

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions exceljs versions prior to 1.6.0
Description The issue is related to an unescaped payload in exceljs, allowing a possible cross-site scripting (XSS) attack via cell value when a worksheet is displayed in a browser. This is due to exceljs not validating data from parsed XLSX files and embedding HTML tags, like
Recommendations Update to version 1.6.0 or later. As a temporary workaround, consider restricting the display of potentially malicious Excel files in browsers until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16459
GHSA-2J2J-8RRV-264G

Affected Products

Exceljs