MEDIUM
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL
Published Jul 26, 2013
4.3
MEDIUMCVSS 2.0
EPSS 1.49%
Description
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Affected products
No data.
OR
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.1.10
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.2.9
- 2.2.10
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.3.6
- 2.3.7
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.5.0
- 3.0.0
- 3.1.0
- 3.1.1
- 3.1.2
- 3.2.0
- 3.3.0
- 3.4.0
- 3.4.1
- 3.5.0
- 3.5.1
- 3.6.0
- 3.7.0
- 3.7.1
- 3.7.2
- 3.7.3
- 3.8.0
- 3.8.1
- 3.9.0
- 3.9.1
- 3.10.0
- 3.10.1
- 3.10.2
No data.
No Red Hat product state for this CVE.
yui
npm
Introduced 0 Fixed 3.10.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | yui | 0 | 3.10.3 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-39678 x_refsource_CONFIRM
- http://yuilibrary.com/support/20130515-vulnerability/ x_refsource_CONFIRMPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1179 Advisory
- https://github.com/advisories/GHSA-mj87-8xf8-fp4w Advisory
- https://lists.apache.org/thread.html/72837f969cdf9b63a7e7337edd069fa3b3950eea7c997cc2ff61aa0c%40%3Cissues.zookeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/72837f969cdf9b63a7e7337edd069fa3b3950eea7c997cc2ff61aa0c@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/d8b9403dbab85a51255614949938b619bd03b1c944c76c48c6996a0e%40%3Cdev.zookeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/d8b9403dbab85a51255614949938b619bd03b1c944c76c48c6996a0e@%3Cdev.zookeeper.apache.org%3E
- https://moodle.org/mod/forum/discuss.php?d=232496 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4939
- https://www.npmjs.com/advisories/332
- https://yuilibrary.com/support/20130515-vulnerability/
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 26, 2013
Updated Aug 6, 2024
Reserved Jul 26, 2013
Link CVE-2013-4939
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-1179 GHSA-MJ87-8XF8-FP4W Assigner mitre
Published Jul 26, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2020-1179