CVE-2013-4942: XSS
Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4942?
CVE-2013-4942 has a medium severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-4942?
To fix CVE-2013-4942, upgrade your Yahoo YUI version to 3.10.2 or later, or apply the relevant patches in Moodle.
Which versions are affected by CVE-2013-4942?
CVE-2013-4942 affects Moodle versions 2.1.0 through 2.5.0 and Yahoo YUI versions 3.5.0 through 3.9.1.
What is CVE-2013-4942?
CVE-2013-4942 is a cross-site scripting (XSS) vulnerability in the Uploader component of Yahoo's YUI used in Moodle.
Can CVE-2013-4942 lead to any consequences?
Yes, CVE-2013-4942 can allow remote attackers to inject arbitrary web script or HTML into affected applications.