Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue and SimpleXLSX::toHTMLEx
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Dec 21, 2024 
          in
          
            shuchkin/simplexlsx
          
          •
          Updated Dec 23, 2024 
      
  
Package
Affected versions
>= 1.0.12, < 1.1.13
  Patched versions
1.1.13
  Description
        Published by the National Vulnerability Database
      Dec 23, 2024 
    
  
        Published to the GitHub Advisory Database
      Dec 23, 2024 
    
  
        Reviewed
      Dec 23, 2024 
    
  
        Last updated
      Dec 23, 2024 
    
  
Impact
When calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code.
Patches
The supplied patch resolves this vulnerability for SimpleXLSX. Use 1.1.13
Workarounds
Don't use data publication via toHTMLEx
This vulnerability was discovered by Aleksey Solovev (Positive Technologies)
References