4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
0.003 Low
EPSS
Percentile
65.6%
The YUI team reports:
Vulnerability in YUI 2.4.0 through YUI 2.9.0
A XSS vulnerability has been discovered in some YUI 2 .swf files
from versions 2.4.0 through 2.9.0. This defect allows JavaScript
injection exploits to be created against domains that host affected
YUI .swf files.
If your site loads YUI 2 from a CDN (yui.yahooapis.com,
ajax.googleapis.com, etc.) and not from your own domain, you
are not affected. YUI 3 is not affected by this issue.