Description
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2019-20174
https://github.com/auth0/lock/releases/tag/v11.21.0
Related Vulnerabilities
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-30515 Vulnerability in maven package io.jenkins.plugins:thycotic-devops-secrets-vault
CVE-2020-36048 Vulnerability in maven package org.webjars.bower:engine.io
CVE-2023-0674 Vulnerability in maven package com.xuxueli:xxl-job-core
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-standard-processors