Reflect XSS Issue in Lock.js

Overview

The user input fields in the sign up page are vulnerable to HTML and XSS injection.

Applies To

  • Lock.js
  • HTML
  • XSS injection

Cause

The customer was using lock 11.27.2


Troubleshooting

  • Check lock.js version

Solution

Update Lock.js to the latest version.
This issue has been resolved.

https://auth0.com/docs/secure/security-guidance/security-bulletins/cve-2021-32641

Recommended content

No recommended content found...