Vulnerabilities/

auth0-lock vulnerable to XSS via unsanitized placeholder property

Severity:
Medium

Description

Auth0 Lock version 11.20.4 and earlier did not properly sanitize the generated HTML code. Customers using the additionalSignUpFields customization option to add a checkbox to the sign-up dialog that are passing a placeholder property obtained from an untrusted source (e.g.

Recommendation

Update the auth0-lock package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
auth0-lock
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing