Executive brief
Yahoo YUI is a popular JavaScript framework used in web applications like Moodle to handle network I/O operations. This vulnerability allows attackers to inject malicious JavaScript code into web pages through a crafted URL, which could lead to theft of user credentials, session hijacking, or distribution of malware to end users.
Technical details
This is a cross-site scripting (XSS) vulnerability (CWE-79) in the io.swf Flash component of Yahoo YUI's IO Utility. The vulnerability exists in how the component processes URL parameters, failing to properly sanitize user-supplied input. An attacker can craft a malicious URL containing arbitrary JavaScript that gets reflected in the page without proper encoding. The attack requires user interaction (clicking a malicious link) but no authentication. When an unpatched YUI version is deployed in applications like Moodle, the XSS payload executes in the victim's browser with the privileges of the hosting page. Patches are available: YUI 3.10.11 or later, or Moodle 2.2.11+, 2.3.8+, 2.4.5+, 2.5.1+.
Affected products
- Yahoo YUI 3.0.0 through 3.10.10, 3.10.12
- Moodle Moodle through 2.1.10; 2.2.0 through 2.2.10; 2.3.0 through 2.3.7; 2.4.0-rc1 through 2.4.4; 2.5.0-beta through 2.5.0
Timeline
- 2013-07-29: disclosed
- 2022-05-13: advisory: GitHub security advisory published