Vulnerabilities/

Reflected XSS when using flashMessages or languageDictionary

Severity:
High

Description

Versions before and including 11.30.0 are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library’s

Recommendation

Update the auth0-lock package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
auth0-lock
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing