PT-2024-36597 · Unknown · Simplexlsx

Aleksey Solovev

·

Published

2024-12-12

·

Updated

2024-12-13

·

CVE-2024-55878

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SimpleXLSX versions 1.0.12 through 1.1.12
Description The issue allows for the execution of arbitrary JavaScript code when calling the extended toHTMLEx method. This can be exploited in versions prior to 1.1.12. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited. The technical details of the exploitation include the toHTMLEx method, which can execute arbitrary JavaScript code.
Recommendations For versions 1.0.12 through 1.1.12, update to version 1.1.12 to resolve the issue. As a temporary workaround, consider not using direct publication via the toHTMLEx method until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-55878
GHSA-X6MH-RJWM-8PH7

Affected Products

Simplexlsx