Description
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
Remediation
References
https://github.com/alibaba/nacos/issues/7359
Related Vulnerabilities
CVE-2013-2071 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2018-11011 Vulnerability in maven package cc.ryanc:halo
CVE-2023-35165 Vulnerability in npm package @aws-cdk/aws-eks
CVE-2022-43424 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto