Junglewise Threat Intelligence

CVE-2013-4942: Yahoo YUI flashuploader.swf cross-site scripting

CVE-2013-4942 · Severity: medium · CVSS 4 · Published 2022-05-13

Technologies: Moodle. Vendors: Moodle.

Executive brief

Yahoo's YUI library includes a Flash-based file uploader component that is vulnerable to cross-site scripting (XSS) attacks. An attacker can craft a malicious URL that injects arbitrary JavaScript code into a web page, allowing them to steal user sessions, steal credentials, deface content, or perform actions on behalf of the victim.

Technical details

A cross-site scripting (CWE-79) vulnerability exists in the flashuploader.swf component of Yahoo's YUI library versions 3.2.0 through 3.9.1. The vulnerability is triggered by improper handling of crafted URL parameters passed to the Flash uploader, allowing injection of arbitrary web script or HTML. The attack requires user interaction (clicking a malicious link) but no authentication. An attacker can exploit this by crafting a URL containing XSS payload that will execute in the context of the victim's browser session. Patches are available in YUI versions after 3.9.1 and Moodle versions 2.2.11, 2.3.8, 2.4.5, and 2.5.1.

Affected products

  • Yahoo YUI 3.2.0 through 3.9.1
  • Moodle Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1

Timeline

  • 2013-07-29: disclosed: Vulnerability disclosed to NVD
  • 2013: patched: Patches released for affected Moodle versions
  • 2022-05-13: advisory: GHSA advisory published

References

Related threats