Steps to Reproduce
- load blank file
- enter <img src=a onerror='alert(document.domain)'> in the formular bar
2nd case: Steps to Reproduce
- load keikai-841.xlsx
Current Result
a browser executes the js and shows a popup
Expected Result
no js executed
Debug Information
- input the same string in a cell editbox also has the same bug
- attackers can upload an xlsx with malicious code and execute it in a browser.
- is blocked by
-
KEIKAI-688 Support formula autocomplete and argument hints
-
- Closed
-