Описание
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 2.5.1-1 |
esm-apps/xenial | not-affected | 2.5.1-1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [2.5.1-1]] |
lucid | ignored | end of life |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
quantal | ignored | end of life |
raring | ignored | end of life |
saucy | not-affected | 2.5.1-1 |
trusty | not-affected | 2.5.1-1 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL.
Cross-site scripting (XSS) vulnerability in uploader.swf in the Upload ...
EPSS
4.3 Medium
CVSS2