Description
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
Remediation
References
https://github.com/alibaba/nacos/issues/7359
Related Vulnerabilities
CVE-2020-7691 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2023-42278 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-22881 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-server
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable