Description
The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.
Remediation
References
https://nodesecurity.io/advisories/43
http://www.openwall.com/lists/oss-security/2016/04/20/11
http://www.securityfocus.com/bid/97102
Related Vulnerabilities
CVE-2023-40339 Vulnerability in maven package org.jenkins-ci.plugins:config-file-provider
CVE-2018-14041 Vulnerability in npm package bootstrap
CVE-2023-43795 Vulnerability in maven package org.geoserver.extension:gs-wps-core
CVE-2022-45396 Vulnerability in maven package com.thalesgroup.hudson.plugins:sourcemonitor
CVE-2018-20594 Vulnerability in maven package org.hswebframework.web:hsweb-system-workflow-local