In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
{ "cpe": "cpe:2.3:a:ant.design:ant_design_pro:4.0.0:*:*:*:*:*:*:*", "source": "CPE_STRING", "extracted_events": [ { "introduced": "4.0.0" }, { "last_affected": "4.0.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18350.json"