PT-2024-9826 · Unknown · Simplexlsx

Aleksey Solovev

·

Published

2024-12-17

·

Updated

2024-12-23

·

CVE-2024-56364

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SimpleXLSX versions 1.0.12 through 1.1.13
Description: The issue is related to the execution of arbitrary JavaScript code when calling the extended toHTMLEx method in SimpleXLSX. This can allow a remote attacker to execute arbitrary JavaScript code. The vulnerability is associated with the lack of protection measures for the web page structure.
Recommendations: For SimpleXLSX versions 1.0.12 through 1.1.12, update to version 1.1.13 to resolve the issue. As a temporary workaround, consider avoiding the use of the toHTMLEx method until the issue is resolved. Do not use data publication via toHTMLEx until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-11603
CVE-2024-56364
GHSA-R87Q-FJ25-F8JF

Affected Products

Simplexlsx