Intel

AIKIDO-2025-10190

shuchkin/simplexlsx is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2024-56364 Published Mar 28, 2025

45

Medium Risk

This Affects:

phpshuchkin/simplexlsx
1.0.12 - 1.1.12
Fixed in 1.1.13
Are you affected? Scan for Free

TL;DR

Affected versions of this package fail to properly validate CSS from external files, creating a potential security risk. Attackers can exploit this vulnerability by crafting malicious files, which could lead to Cross-site Scripting (XSS) attacks, potentially compromising user data or application integrity.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

shuchkin/simplexlsx is vulnerable to Improper Input Validation in versions 1.0.12 - 1.1.12.

How to fix this

Upgrade the shuchkin/simplexlsx library to the patch version.