Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. yui
  4. ›
  5. CVE-2013-4939

CVE-2013-4939: XSS via .swf files

July 29, 2013 (updated November 7, 2019)

In the vulnerable versions, the uploader.swf and io.swf utilities contain a vulnerability allowing cross-site scripting through the .swf files used in these components. Through a url accessing these files, and attacker can inject script in the context of these files, potentially exposing cookies or other sensitive information. The vulnerability resurfaced in v0.10.2, but only with io.swf.

References

  • yuilibrary.com/support/20130515-vulnerability

Code Behaviors & Features

Detect and mitigate CVE-2013-4939 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.0.0 before 3.10.0, version 3.10.2

Fixed versions

  • 3.10.0
  • 3.10.3

Solution

It's recommended to 1. delete self-hosted copies of these files if you are not using them, 2.use the Yahoo! CDN hosted files and 3. use the patched files provided on the YUI Library; see provided link.

Impact 4.3 MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

npm/yui/CVE-2013-4939.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:56 +0000.