GHSA-wvv5-5g6x-hp7j

Suggest an improvement
Source
https://github.com/advisories/GHSA-wvv5-5g6x-hp7j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-wvv5-5g6x-hp7j/GHSA-wvv5-5g6x-hp7j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wvv5-5g6x-hp7j
Aliases
  • CVE-2025-60837
Published
2025-10-23T21:31:43Z
Modified
2025-10-23T22:44:43.351562Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
MCMS reflected cross-site scripting (XSS) vulnerability
Details

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

Database specific
{
    "nvd_published_at": "2025-10-23T19:15:50Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-23T22:21:11Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / net.mingsoft:ms-mcms

Package

Name
net.mingsoft:ms-mcms
View open source insights on deps.dev
Purl
pkg:maven/net.mingsoft/ms-mcms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.0.1

Affected versions

4.*
4.6.3-SNAPSHOTS
4.6.5
4.7.1
4.7.2
5.*
5.0.0
5.0.1
5.1
5.2
5.2.0
5.2.0.RELEASE
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
5.2.10
5.2.11
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.5.0
6.*
6.0.0
6.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-wvv5-5g6x-hp7j/GHSA-wvv5-5g6x-hp7j.json"