Description
All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
Remediation
References
https://github.com/myliang/x-spreadsheet/issues/580
https://security.snyk.io/vuln/SNYK-JS-XDATASPREADSHEET-2430381
https://youtu.be/Ij-8VVKNh7U
Related Vulnerabilities
CVE-2023-0044 Vulnerability in maven package io.quarkus:quarkus-security-webauthn
CVE-2020-7793 Vulnerability in maven package org.webjars.bowergithub.faisalman:ua-parser-js
CVE-2021-41164 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2022-39396 Vulnerability in npm package parse-server
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-api