Junglewise Threat Intelligence

CVE-2013-4940: Yahoo YUI Cross-site Scripting in io.swf

CVE-2013-4940 · Severity: medium · CVSS 4 · Published 2022-05-13

Technologies: Moodle. Vendors: Moodle.

Executive brief

Yahoo YUI is a popular JavaScript framework used in web applications like Moodle to handle network I/O operations. This vulnerability allows attackers to inject malicious JavaScript code into web pages through a crafted URL, which could lead to theft of user credentials, session hijacking, or distribution of malware to end users.

Technical details

This is a cross-site scripting (XSS) vulnerability (CWE-79) in the io.swf Flash component of Yahoo YUI's IO Utility. The vulnerability exists in how the component processes URL parameters, failing to properly sanitize user-supplied input. An attacker can craft a malicious URL containing arbitrary JavaScript that gets reflected in the page without proper encoding. The attack requires user interaction (clicking a malicious link) but no authentication. When an unpatched YUI version is deployed in applications like Moodle, the XSS payload executes in the victim's browser with the privileges of the hosting page. Patches are available: YUI 3.10.11 or later, or Moodle 2.2.11+, 2.3.8+, 2.4.5+, 2.5.1+.

Affected products

  • Yahoo YUI 3.0.0 through 3.10.10, 3.10.12
  • Moodle Moodle through 2.1.10; 2.2.0 through 2.2.10; 2.3.0 through 2.3.7; 2.4.0-rc1 through 2.4.4; 2.5.0-beta through 2.5.0

Timeline

  • 2013-07-29: disclosed
  • 2022-05-13: advisory: GitHub security advisory published

References

Related threats