Description
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
Remediation
References
https://github.com/ant-design/ant-design-pro/pull/5461
Related Vulnerabilities
CVE-2023-34238 Vulnerability in npm package gatsby-cli
CVE-2022-34662 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2023-35166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-help-ui
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat:catalina