CVE-2019-20174
MEDIUMAuth0 Lock < 11.21.0 - Cross-Site Scripting via Additional Sign-Up Fields Placeholder
Title source: llmDescription
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
References (2)
Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/auth0/lock/releases/tag/v11.21.0
Exploit, Vendor Advisory x_refsource_confirm
https://auth0.com/docs/security/bulletins/cve-2019-20174
Scores
CVSS v3
6.1
EPSS
0.0072
EPSS Percentile
50.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
auth0/lock
< 11.21.0
npm/auth0-lock
0 - 11.21.0npm
Published
Feb 03, 2020
Tracked Since
Feb 18, 2026