GHSA-64cm-3cj3-67hf

Suggest an improvement
Source
https://github.com/advisories/GHSA-64cm-3cj3-67hf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-64cm-3cj3-67hf/GHSA-64cm-3cj3-67hf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-64cm-3cj3-67hf
Aliases
  • CVE-2024-33748
Published
2024-05-07T18:30:33Z
Modified
2024-07-05T21:01:59.192953Z
Severity
  • 4.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N CVSS Calculator
Summary
MS Basic Cross-site Scripting vulnerability
Details

Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.

Database specific
{
    "nvd_published_at": "2024-05-07T16:15:07Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-07T19:59:12Z"
}
References

Affected packages

Maven / net.mingsoft:ms-basic

Package

Name
net.mingsoft:ms-basic
View open source insights on deps.dev
Purl
pkg:maven/net.mingsoft/ms-basic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.1.13.4

Affected versions

1.*

1.0.0
1.0.1
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.31
1.0.32
1.0.33
1.0.34
1.0.35
1.0.36
1.0.37
1.0.38

2.*

2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.10
2.1.11
2.1.12
2.1.13
2.1.13.1
2.1.13.2
2.1.13.3
2.1.13.4