Lucene search

K
osvGoogleOSV:GHSA-JJG9-MF63-VQRP
HistoryMay 17, 2022 - 1:38 a.m.

Cross-site scripting in yui 2.4.0

2022-05-1701:38:30
Google
osv.dev
5

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.2%

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

CPENameOperatorVersion
yui2le2.9.0
yui2ge2.4.0

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.2%