Loading HuntDB...

GHSA-rxvj-5mv6-j5mc

GitHub Security Advisory

Cross-site Scripting in Mingsoft MCMS

✓ GitHub Reviewed LOW Has CVE

Advisory Details

A Cross-site Scripting vulnerability has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-235611.

Affected Packages

Maven net.mingsoft:ms-mcms
Affected versions: 0 (fixed in 5.3.2)

Related CVEs

Key Information

GHSA ID
GHSA-rxvj-5mv6-j5mc
Published
July 28, 2023 9:30 AM
Last Modified
July 28, 2023 8:44 PM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
net.mingsoft:ms-mcms
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 31, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.