{"id":"GHSA-64cm-3cj3-67hf","summary":"MS Basic Cross-site Scripting vulnerability","details":"Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.","aliases":["CVE-2024-33748"],"modified":"2024-07-05T21:01:59.192953Z","published":"2024-05-07T18:30:33Z","database_specific":{"nvd_published_at":"2024-05-07T16:15:07Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-07T19:59:12Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33748"},{"type":"WEB","url":"https://github.com/Fr1ezy/Fr1ezy-ms-basic_XSS"},{"type":"WEB","url":"https://mvnrepository.com/artifact/net.mingsoft/ms-basic"}],"affected":[{"package":{"name":"net.mingsoft:ms-basic","ecosystem":"Maven","purl":"pkg:maven/net.mingsoft/ms-basic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.1.13.4"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.20","1.0.21","1.0.22","1.0.23","1.0.24","1.0.25","1.0.26","1.0.27","1.0.28","1.0.29","1.0.30","1.0.31","1.0.32","1.0.33","1.0.34","1.0.35","1.0.36","1.0.37","1.0.38","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.13.1","2.1.13.2","2.1.13.3","2.1.13.4","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-64cm-3cj3-67hf/GHSA-64cm-3cj3-67hf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"}]}