PT-2024-36597 · Unknown · Simplexlsx
Aleksey Solovev
·
Published
2024-12-12
·
Updated
2024-12-13
·
CVE-2024-55878
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SimpleXLSX versions 1.0.12 through 1.1.12
Description
The issue allows for the execution of arbitrary JavaScript code when calling the extended
toHTMLEx method. This can be exploited in versions prior to 1.1.12. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited. The technical details of the exploitation include the toHTMLEx method, which can execute arbitrary JavaScript code.Recommendations
For versions 1.0.12 through 1.1.12, update to version 1.1.12 to resolve the issue.
As a temporary workaround, consider not using direct publication via the
toHTMLEx method until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplexlsx