CVE-2013-7454: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
References
- blog.kotowicz.net/2012/07/codeigniter-210-xssclean-cross-site.html
- www.openwall.com/lists/oss-security/2016/04/20/11
- github.com/advisories/GHSA-q4qq-fm7q-cwp5
- nealpoole.com/blog/2013/07/xss-filter-bypass-in-validator-nodejs-module/
- nodesecurity.io/advisories/41
- nvd.nist.gov/vuln/detail/CVE-2013-7454
- www.npmjs.com/advisories/41
Detect and mitigate CVE-2013-7454 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →