Vulnerabilities/

DOM-based XSS in auth0-lock

Severity:
Low

Description

Versions before and including 11.25.1 are using dangerouslySetInnerHTML to display an informational message when used with a Passwordless or Enterprise connection.

Recommendation

Update the auth0-lock package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
auth0-lock
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing