First published: Mon Jan 23 2017(Updated: )
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Langgenius Dify Node.js | <=1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7454 is classified as a moderate severity vulnerability affecting the validator module for Node.js.
To fix CVE-2013-7454, upgrade the validator module to version 1.1.0 or later.
Remote attackers can exploit CVE-2013-7454 to bypass the cross-site scripting (XSS) filter in affected applications.
Versions of Node.js prior to 1.1.0 are vulnerable to CVE-2013-7454.
CVE-2013-7454 allows bypassing of the XSS filter through nested forbidden strings, posing a security risk.