CVE-2024-56364 Information

Description

SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13 when calling the extended toHTMLEx method it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13.

Reference

https://github.com/shuchkin/simplexlsx/commit/71a5e3d40d14e33161f8a40b3fd02de542218ef0 https://github.com/shuchkin/simplexlsx/security/advisories/GHSA-r87q-fj25-f8jf

Share on: