{"id":"CVE-2019-18350","details":"In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.","modified":"2026-07-08T16:27:19.983082Z","published":"2019-10-23T18:15:11.727Z","references":[{"type":"FIX","url":"https://github.com/ant-design/ant-design-pro/pull/5461"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ant-design/ant-design-pro","events":[{"introduced":"d52f171832797b26e02d87335d20da6f06630a7e"},{"last_affected":"d52f171832797b26e02d87335d20da6f06630a7e"}],"database_specific":{"cpe":"cpe:2.3:a:ant.design:ant_design_pro:4.0.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"last_affected":"4.0.0"}],"source":"CPE_STRING"}}],"versions":["4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18350.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}