CVE-2013-4940: XSS
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4940?
CVE-2013-4940 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-4940?
To fix CVE-2013-4940, update your version of the Yahoo! YUI library to at least 3.10.3 or upgrade Moodle to a version higher than 2.5.1.
Which software is affected by CVE-2013-4940?
CVE-2013-4940 affects Yahoo! YUI version 3.10.2 and various Moodle versions from 2.1.10 to 2.5.0.
Can CVE-2013-4940 lead to data theft?
Yes, CVE-2013-4940 can allow attackers to inject arbitrary web scripts, potentially leading to data theft or session hijacking.
What should I do if I cannot update to fix CVE-2013-4940?
If you cannot update, consider implementing input validation and output encoding to mitigate the effects of CVE-2013-4940.