QID 983408
QID 983408: Nodejs (npm) Security Update for exceljs (GHSA-2j2j-8rrv-264g)
Versions of `exceljs` before 1.6.0 are vulnerable to cross-site scripting.
This vulnerability is due to `exceljs` does not validate data from parsed XLSX file and allows to embed HTML tags, like `<script>`, directly in the sheet cells. Because of this it's possible to inject malicious JavaScript code and execute it when data from the sheet were displayed in the browser.
## Recommendation
Update to version 1.6.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2j2j-8rrv-264g for updates pertaining to this vulnerability.
Vendor References
- GHSA-2j2j-8rrv-264g -
github.com/advisories/GHSA-2j2j-8rrv-264g
CVEs related to QID 983408
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2j2j-8rrv-264g | exceljs |
|