Description
All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-XDATASPREADSHEET-2430381
https://github.com/myliang/x-spreadsheet/issues/580
https://youtu.be/Ij-8VVKNh7U
Related Vulnerabilities
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2020-35202 Vulnerability in maven package org.igniterealtime.openfire.plugins:dbaccess
CVE-2021-40146 Vulnerability in maven package org.apache.any23:apache-any23-core