Description
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
Remediation
References
https://github.com/ant-design/ant-design-pro/pull/5461
Related Vulnerabilities
CVE-2022-36033 Vulnerability in maven package org.jsoup:jsoup
CVE-2021-23507 Vulnerability in npm package object-path-set
CVE-2020-7760 Vulnerability in maven package org.webjars.npm:codemirror
CVE-2023-24620 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans
CVE-2022-35915 Vulnerability in npm package openzeppelin-eth