Description
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 3.2.0, <= 3.9.1
References
- GHSA-64r3-582j-frqm
- moodle.org
- git.moodle.org
- web.archive.org
- CVE-2013-4941
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- YUI Cross-site Scripting (XSS) vulnerability - CVE-2013-4942
- YUI Cross-site Scripting (XSS) vulnerability - yui - GHSA-x5hj-47vv-53p8 - CVE-2013-4940
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component - CVE-2025-8082
You might also like:
- Tags:
- npm
- yui
Anything's wrong? Let us know Last updated on April 12, 2025


