PT-2024-36597 · Unknown · Simplexlsx

·

CVE-2024-55878

·

Published

2024-12-12

·

Updated

2024-12-13

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SimpleXLSX versions 1.0.12 through 1.1.12
Description The issue allows for the execution of arbitrary JavaScript code when calling the extended toHTMLEx method. This can be exploited in versions prior to 1.1.12. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited. The technical details of the exploitation include the toHTMLEx method, which can execute arbitrary JavaScript code.
Recommendations For versions 1.0.12 through 1.1.12, update to version 1.1.12 to resolve the issue. As a temporary workaround, consider not using direct publication via the toHTMLEx method until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55878
GHSA-X6MH-RJWM-8PH7

Affected Products

Simplexlsx