Description
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
Remediation
References
https://github.com/ant-design/ant-design-pro/pull/5461
Related Vulnerabilities
CVE-2022-45388 Vulnerability in maven package net.praqma:config-rotator
CVE-2023-34464 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web
CVE-2007-6433 Vulnerability in maven package org.jboss.seam:jboss-seam
CVE-2022-31172 Vulnerability in npm package @openzeppelin/contracts-upgradeable