Showing 3 vulnerabilities on this page for lock

Signals CISA KEV Ransomware Nuclei
auth0 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

HTML injection with additional signup fields

Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `11.33.0`, when the “additional signup fields” feature [is configured](https://github.com/auth0/lock#additional-sign-up-fields), a malicious actor can inject invalidated HTML code into these additional fields, which is then stored in the service `user_metdata` payload (using the `name` property). Verification emails, when

CWE-79May 5, 2022
CVSS6.1v3.1EPSS0.598%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Reflected XSS when using flashMessages

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.

CWE-79Jun 4, 2021
CVSS8.1v3.1EPSS1.54%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

DOM-based XSS in auth0-lock

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

CWE-79Aug 19, 2020
CVSS6.4v3.1EPSS0.546%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX