MEDIUM
Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL
Published Jul 26, 2013
5.3
MEDIUMCVSS 4.0
EPSS 1.19%
Description
Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Affected products
No data.
OR
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.1.10
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.2.9
- 2.2.10
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.3.6
- 2.3.7
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.5.0
- 3.5.0
- 3.5.1
- 3.6.0
- 3.7.0
- 3.7.1
- 3.7.2
- 3.7.3
- 3.8.0
- 3.8.1
- 3.9.0
- 3.9.1
- 3.10.0
- 3.10.1
- 3.10.2
No data.
No Red Hat product state for this CVE.
yui
npm
Introduced 3.2.0 Fixed not fixedmoodle/moodle
Packagist
Introduced 2.5.0-beta Fixed 2.5.1moodle/moodle
Packagist
Introduced 0 Fixed 2.2.11moodle/moodle
Packagist
Introduced 2.3.0 Fixed 2.3.8moodle/moodle
Packagist
Introduced 2.4.0-rc1 Fixed 2.4.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | yui | 3.2.0 | not fixed |
| Packagist | moodle/moodle | 2.5.0-beta | 2.5.1 |
| Packagist | moodle/moodle | 0 | 2.2.11 |
| Packagist | moodle/moodle | 2.3.0 | 2.3.8 |
| Packagist | moodle/moodle | 2.4.0-rc1 | 2.4.5 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-39678 x_refsource_CONFIRM
- http://yuilibrary.com/support/20130515-vulnerability/ x_refsource_CONFIRMPatchVendor Advisory
- https://github.com/advisories/GHSA-9ww8-j8j2-3788 Advisory
- https://moodle.org/mod/forum/discuss.php?d=232496 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4942
- https://web.archive.org/web/20130909203912/http://yuilibrary.com/support/20130515-vulnerability
| Link | Providers | Tags |
|---|---|---|
| http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-39678 | x_refsource_CONFIRM | |
| http://yuilibrary.com/support/20130515-vulnerability/ | x_refsource_CONFIRMPatchVendor Advisory | |
| https://github.com/advisories/GHSA-9ww8-j8j2-3788 | Advisory | |
| https://moodle.org/mod/forum/discuss.php?d=232496 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4942 | ||
| https://web.archive.org/web/20130909203912/http://yuilibrary.com/support/20130515-vulnerability |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 26, 2013
Updated Sep 16, 2024
Reserved Jul 26, 2013
Link CVE-2013-4942
CISA Vulnrichment
GHSA-9WW8-J8J2-3788 Updated n/a