The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of values or DoS the affected spreadsheet. Disclosure of secrets or other system settings is not affected as well as other spreadsheets still work as expected.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.areal-topkapi.com/en/topkapi/security-bulletins | vendor advisory |
https://www.areal-topkapi.com/topkapi/bulletins-de-securite | vendor advisory |