Reflect XSS Issue in Lock.js
Last Updated:
Overview
The user input fields in the sign up page are vulnerable to HTML and XSS injection.
Applies To
- Lock.js
- HTML
- XSS injection
Cause
The customer was using lock 11.27.2
Troubleshooting
- Check lock.js version
Solution
Update Lock.js to the latest version.
This issue has been resolved.
https://auth0.com/docs/secure/security-guidance/security-bulletins/cve-2021-32641