VYPR
Medium severity6.4NVD Advisory· Published Aug 20, 2020· Updated Jun 17, 2026

CVE-2020-15119

CVE-2020-15119

Description

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
auth0-locknpm
< 11.26.311.26.3

Affected products

3
  • Auth0/Lock2 versions
    cpe:2.3:a:auth0:lock:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:auth0:lock:*:*:*:*:*:*:*:*range: <=11.25.1
    • (no CPE)range: <= 11.25.1
  • ghsa-coords
    Range: < 11.26.3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.