CVE-2013-4939

Yahoo! YUI 3.0.0-3.9.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.

Scores

EPSS 0.0031
EPSS Percentile 53.9%

Details

CWE
CWE-79
Status published
Products (50)
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 40 more
Published Jul 29, 2013
Tracked Since Feb 18, 2026