VDB
Sign up
MEDIUM6.8

GHSA-x6mh-rjwm-8ph7

Cross-site Scripting vulnerability in SimpleXLSXEx::readXfs and SimpeXLSX::toHTMLEx

Quick fix

GHSA-x6mh-rjwm-8ph7 — shuchkin/simplexlsx: upgrade to the fixed version with the command below.

composer require shuchkin/simplexlsx:^1.1.12

Details

### Impact When calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code.

### Patches The supplied patch resolves this vulnerability for SimpleXLSX. Use 1.1.12

### Workarounds Don't use direct publication via toHTMLEx

*** This vulnerability was discovered by Aleksey Solovev (Positive Technologies)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/shuchkin/simplexlsx
Introduced in: 1.0.12Fixed in: 1.1.12
Fixcomposer require shuchkin/simplexlsx:^1.1.12

References