Description
All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
Remediation
References
https://github.com/myliang/x-spreadsheet/issues/580
https://security.snyk.io/vuln/SNYK-JS-XDATASPREADSHEET-2430381
https://youtu.be/Ij-8VVKNh7U
Related Vulnerabilities
CVE-2023-34613 Vulnerability in maven package net.sf.sojo:sojo
CVE-2017-16141 Vulnerability in npm package lab6drewfusbyu
CVE-2021-29943 Vulnerability in maven package org.apache.solr:solr-core
CVE-2019-10768 Vulnerability in npm package angular
CVE-2022-34115 Vulnerability in maven package io.dataease:dataease-plugin-common