PT-2018-13584 · Exceljs · Exceljs
Bl4De
+1
·
Published
2018-09-06
·
Updated
2019-10-09
·
CVE-2018-16459
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
exceljs versions prior to 1.6.0
Description
The issue is related to an unescaped payload in exceljs, allowing a possible cross-site scripting (XSS) attack via cell value when a worksheet is displayed in a browser. This is due to exceljs not validating data from parsed XLSX files and embedding HTML tags, like
Recommendations
Update to version 1.6.0 or later. As a temporary workaround, consider restricting the display of potentially malicious Excel files in browsers until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exceljs