CVE-2013-4941: XSS
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4941?
The severity of CVE-2013-4941 is considered medium due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-4941?
To fix CVE-2013-4941, update to a supported version of Moodle or Yahoo YUI that has patched the vulnerability.
What software is affected by CVE-2013-4941?
CVE-2013-4941 affects versions of Moodle from 2.1.10 to 2.5.0 and Yahoo YUI from 3.2.0 to 3.9.1.
What kind of attack does CVE-2013-4941 facilitate?
CVE-2013-4941 facilitates cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts.
Is CVE-2013-4941 still a threat?
CVE-2013-4941 may still pose a threat if vulnerable software versions remain in use without being updated.