Intel

AIKIDO-2024-10559

simplexlsx is vulnerable to CSS injection

CSS injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

PHPsimplexlsx
0.0.3 - 1.1.12
Fixed in 1.1.13

TL;DR

Affected versions of this package are affected by CSS injection in methods that handle color and theme rendering. Affected versions of this package are affected by CSS injection in methods that handle color and theme rendering. An attacker might take advantage of this vulnerability to create misbehaviors in the application like rendering unallowed ads.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

simplexlsx is vulnerable to CSS injection in versions 0.0.3 - 1.1.12.

How to fix this

Upgrade the simplexlsx library to the patch version.