Vulnerabilities/

Cross-site Scripting in Auth0 Lock

Severity:
Medium

Description

In versions before and including 11.32.2, when the “additional signup fields” feature is configured, a malicious actor can inject invalidated HTML code into these additional fields, which is then stored in the service user_metdata payload (using the name property).

Verification emails, when applicable, are generated using this metadata.

Recommendation

Update the auth0-lock package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
auth0-lock
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing