XSS Filter Bypass in Node.js Validator Module
CVE-2013-7451

6.1MEDIUM

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
23 January 2017

What is CVE-2013-7451?

The validator module for Node.js, prior to version 1.1.0, is susceptible to a Cross-Site Scripting (XSS) vulnerability that enables remote attackers to bypass the XSS filter. This is achievable through the use of nested tags, which can manipulate input in a way that the existing security measures fail to detect, thereby allowing the execution of arbitrary scripts in the context of a user’s session.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.