Description
All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
Remediation
References
https://github.com/myliang/x-spreadsheet/issues/580
https://security.snyk.io/vuln/SNYK-JS-XDATASPREADSHEET-2430381
https://youtu.be/Ij-8VVKNh7U
Related Vulnerabilities
CVE-2020-7795 Vulnerability in npm package get-npm-package-version
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3
CVE-2018-3750 Vulnerability in maven package org.webjars.npm:deep-extend
CVE-2021-32824 Vulnerability in maven package org.apache.dubbo:dubbo-common
CVE-2023-34189 Vulnerability in maven package org.apache.inlong:manager-web