diff --git a/lib/helpers/isValidXss.js b/lib/helpers/isValidXss.js index 951240ee62..52352ffbf9 100644 --- a/lib/helpers/isValidXss.js +++ b/lib/helpers/isValidXss.js @@ -2,7 +2,7 @@ module.exports = function isValidXss(requestURL) { var xssEventRegex = /(\b)on(click|error|load|mouse\w+|key\w+|focus\w?|blur|change|input|drag\w?|resize|dbclick|contextmenu|drop|select|message|scroll)=/; - var xssJSRegex = /javascript|(<\s*)(\/*)script/gi; + var xssJSRegex = /javascript:|(<\s*)(\/*)script/gi; return xssJSRegex.test(requestURL) || xssEventRegex.test(requestURL); };