Versions before and including 11.25.1 are using dangerouslySetInnerHTML to display an informational message when used with a Passwordless or Enterprise connection.
lock widget opens.When Passwordless or Enterprise connection is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.
You are affected by this vulnerability if all of the following conditions apply:
Upgrade to version 11.26.3
The fix provided in patch will not affect your users.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-19T21:02:01Z",
"nvd_published_at": null,
"severity": "LOW"
}