Description
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
Remediation
References
https://github.com/alibaba/nacos/issues/7359
Related Vulnerabilities
CVE-2022-45689 Vulnerability in maven package cn.hutool:hutool-json
CVE-2020-11969 Vulnerability in maven package org.apache.tomee:openejb-core
CVE-2018-1000006 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-7684 Vulnerability in npm package rollup-plugin-serve
CVE-2022-43434 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner