Логотип exploitDog
bind:CVE-2021-32641
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-32641

Количество 2

Количество 2

nvd логотип

CVE-2021-32641

больше 4 лет назад

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-jr3j-whm4-9wwm

больше 4 лет назад

Reflected XSS when using flashMessages or languageDictionary

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-32641

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-jr3j-whm4-9wwm

Reflected XSS when using flashMessages or languageDictionary

CVSS3: 8.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу