Vulnerabilities/

Cross-Site Scripting in exceljs

Severity:
Medium

Description

Versions of exceljs before 1.6.0 are vulnerable to cross-site scripting.

This vulnerability is due to exceljs not validating data from parsed XLSX file and embedding HTML tags, like <script> directly into the sheet cells.

Recommendation

Update the exceljs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
exceljs
Anything's wrong? Let us know Last updated on September 13, 2023

This issue is available in SmartScanner Professional

See Pricing