2017-01-23 21:00:00
mitre
PUBLISHED
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.