mui-datatables@2.0.0-beta-20 vulnerabilities

Datatables for React using Material-UI

  • latest version

    4.3.0

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mui-datatables package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    CSV Injection

    mui-datatables is a data tables component built on Material-UI.

    Affected versions of this package are vulnerable to CSV Injection. CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. When a spreadsheet program is used to open a CSV, any cells starting with '=' will be interpreted by the software as a formula. Maliciously crafted formulas can be used for three key attacks:

    • Hijacking the user's computer by exploiting vulnerabilities in the spreadsheet software.
    • Hijacking the user's computer by exploiting the user's tendency to ignore security warnings in spreadsheets that they downloaded from their own website
    • Exfiltrating contents from the spreadsheet, or other open spreadsheets.

    How to fix CSV Injection?

    Upgrade mui-datatables to version 2.14.0 or higher.

    <2.14.0