CVE-2024-55878

MEDIUM

SimpleXLSX 1.0.12-1.1.12 - Cross-Site Scripting via toHTMLEx Method

Title source: llm
STIX 2.1

Description

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to version 1.1.12, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. Version 1.1.12 fixes the issue. As a workaround, don't use direct publication via toHTMLEx.

Scores

CVSS v3 6.8
EPSS 0.0044
EPSS Percentile 35.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
shuchkin/simplexlsx 1.0.12 - 1.1.12Packagist
shuchkin/simplexlsx >= 1.0.12, < 1.1.12
Published Dec 12, 2024
Tracked Since Feb 18, 2026