JavaScript Code Execution Vulnerability in SimpleXLSX Software
CVE-2024-56364
5.4MEDIUM
What is CVE-2024-56364?
The SimpleXLSX software, utilized for parsing and extracting data from Excel XLSX files, has a security vulnerability that arises when the extended toHTMLEx method is invoked. This flaw allows for the execution of arbitrary JavaScript code, potentially endangering users by enabling malicious scripts to be executed within the context of the application. This vulnerability impacts versions starting from 1.0.12 up to 1.1.13. Users are advised to upgrade to version 1.1.13 or later to mitigate this issue. For further details regarding the vulnerability and its remediation, refer to the official advisory and the relevant commit logs.
Affected Version(s)
simplexlsx >= 1.0.12, < 1.1.13