XSS Filter Bypass via Encoded URLvalidator
validator prior to 2.0.0 contained an xss filter method that is affected by several filter bypasses. This may result in a cross-site scripting vulnerability.
Proof of Concept
However, it does not properly handle cases where characters have been hex-encoded.
will render as:
The package author has decided to remove the xss filter functionality in the latest version of this module. If this feature is not currently being used, you are not affected by the vulnerability. If it is being used, updating to the latest version of the module will break your application.
In order for affected users to mitigate this vulnerability, it is necessary to use an alternative package that provides similar functionality.
publishedAdvisory publishedOct 27th, 2014
reportedInitial report by taku0Oct 17th, 2015