CVE-2024-56364

MEDIUM

SimpleXLSX 1.0.12-1.1.13 - Cross-Site Scripting via toHTMLEx Method

Title source: llm
STIX 2.1

Description

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13.

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
shuchkin/simplexlsx 1.0.12 - 1.1.13Packagist
shuchkin/simplexlsx >= 1.0.12, < 1.1.13
Published Dec 23, 2024
Tracked Since Feb 18, 2026