Intel

AIKIDO-2025-10190

shuchkin/simplexlsx is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2024-56364 Published Mar 28, 2025

45

Medium Risk

This Affects:

phpshuchkin/simplexlsx
1.0.12 - 1.1.12
Fixed in 1.1.13
Are you affected? Scan for Free

TL;DR

Affected versions of this package fail to properly validate CSS from external files, creating a potential security risk. Attackers can exploit this vulnerability by crafting malicious files, which could lead to Cross-site Scripting (XSS) attacks, potentially compromising user data or application integrity.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

shuchkin/simplexlsx is vulnerable to Improper Input Validation in versions 1.0.12 - 1.1.12.

How to fix this

Upgrade the shuchkin/simplexlsx library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform