Junglewise Threat Intelligence

CVE-2012-5881: YUI cross-site scripting in charts.swf component

CVE-2012-5881 · Severity: info · Published 2022-05-17

Vendors: npm.

Executive brief

YUI is a JavaScript library used by web applications to provide interactive UI components. A cross-site scripting (XSS) vulnerability in the Flash-based charts component allows attackers to inject malicious scripts into web pages, potentially stealing user data, session tokens, or performing unauthorized actions on behalf of affected users.

Technical details

A cross-site scripting (XSS) vulnerability (CWE-79) exists in the Flash component infrastructure of YUI, specifically in the charts.swf file. The vulnerability affects versions 2.4.0 through 2.9.0 and allows remote attackers to inject arbitrary web script or HTML through vectors related to the charts component. This is a similar issue to CVE-2010-4207. The vulnerability is network-accessible with no authentication required; an attacker can craft a malicious web page or inject payloads through user input that the charts component fails to sanitize. Patched versions are available in the YUI library updates.

Affected products

  • Yahoo YUI 2.4.0 through 2.9.0

Timeline

  • 2012-10-30: disclosed
  • 2022-05-17: advisory

References