First published: Fri Jul 26 2013(Updated: )
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =2.1.0 | |
Moodle | =2.1.1 | |
Moodle | =2.1.2 | |
Moodle | =2.1.3 | |
Moodle | =2.1.4 | |
Moodle | =2.1.5 | |
Moodle | =2.1.6 | |
Moodle | =2.1.7 | |
Moodle | =2.1.8 | |
Moodle | =2.1.9 | |
Moodle | =2.1.10 | |
Moodle | =2.2.0 | |
Moodle | =2.2.1 | |
Moodle | =2.2.2 | |
Moodle | =2.2.3 | |
Moodle | =2.2.4 | |
Moodle | =2.2.5 | |
Moodle | =2.2.6 | |
Moodle | =2.2.7 | |
Moodle | =2.2.8 | |
Moodle | =2.2.9 | |
Moodle | =2.2.10 | |
Moodle | =2.3.0 | |
Moodle | =2.3.1 | |
Moodle | =2.3.2 | |
Moodle | =2.3.3 | |
Moodle | =2.3.4 | |
Moodle | =2.3.5 | |
Moodle | =2.3.6 | |
Moodle | =2.3.7 | |
Moodle | =2.4.0 | |
Moodle | =2.4.1 | |
Moodle | =2.4.2 | |
Moodle | =2.4.3 | |
Moodle | =2.4.4 | |
Moodle | =2.5.0 | |
Yahoo Yui | =3.0.0 | |
Yahoo Yui | =3.1.0 | |
Yahoo Yui | =3.1.1 | |
Yahoo Yui | =3.1.2 | |
Yahoo Yui | =3.2.0 | |
Yahoo Yui | =3.3.0 | |
Yahoo Yui | =3.4.0 | |
Yahoo Yui | =3.4.1 | |
Yahoo Yui | =3.5.0 | |
Yahoo Yui | =3.5.1 | |
Yahoo Yui | =3.6.0 | |
Yahoo Yui | =3.7.0 | |
Yahoo Yui | =3.7.1 | |
Yahoo Yui | =3.7.2 | |
Yahoo Yui | =3.7.3 | |
Yahoo Yui | =3.8.0 | |
Yahoo Yui | =3.8.1 | |
Yahoo Yui | =3.9.0 | |
Yahoo Yui | =3.9.1 | |
Yahoo Yui | =3.10.0 | |
Yahoo Yui | =3.10.1 | |
Yahoo Yui | =3.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4939 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2013-4939, upgrade to a patched version of Moodle or Yahoo! YUI that addresses this vulnerability.
CVE-2013-4939 affects Yahoo! YUI versions 3.0.0 through 3.9.1 and Moodle versions before 2.2.11, 2.3.8, 2.4.5, 2.5.1, and others.
CVE-2013-4939 is a cross-site scripting (XSS) vulnerability that can allow remote attackers to inject arbitrary web scripts.
Yes, CVE-2013-4939 can be exploited by attackers to execute malicious scripts in the context of users' browsers.