VDB
Sign up
MEDIUM6.8

GHSA-r87q-fj25-f8jf

Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue and SimpleXLSX::toHTMLEx

Quick fix

GHSA-r87q-fj25-f8jf — shuchkin/simplexlsx: upgrade to the fixed version with the command below.

composer require shuchkin/simplexlsx:^1.1.13

Details

### Impact When calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code.

### Patches The supplied patch resolves this vulnerability for SimpleXLSX. Use 1.1.13

### Workarounds Don't use data publication via toHTMLEx

*** This vulnerability was discovered by Aleksey Solovev (Positive Technologies)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shuchkin/simplexlsx
Introduced in: 1.0.12Fixed in: 1.1.13
Fixcomposer require shuchkin/simplexlsx:^1.1.13

References