CVE-2013-7454: XSS
Published Jan 23, 2017
·Updated
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
Affected Software
1 affected component
Nodejs Node.js<=1.0.4
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7454?
CVE-2013-7454 is classified as a moderate severity vulnerability affecting the validator module for Node.js.
2
How do I fix CVE-2013-7454?
To fix CVE-2013-7454, upgrade the validator module to version 1.1.0 or later.
3
Who can be affected by CVE-2013-7454?
Remote attackers can exploit CVE-2013-7454 to bypass the cross-site scripting (XSS) filter in affected applications.
4
Which versions of Node.js are vulnerable to CVE-2013-7454?
Versions of Node.js prior to 1.1.0 are vulnerable to CVE-2013-7454.
5
What is the nature of the vulnerability in CVE-2013-7454?
CVE-2013-7454 allows bypassing of the XSS filter through nested forbidden strings, posing a security risk.