First published: Thu Dec 01 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the Adobe Flex SDK 3.x and 4.x before 4.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the loading of modules from different domains.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flex SDK | =3.1 | |
Adobe Flex SDK | =3.4.1 | |
Adobe Flex SDK | =3.5a | |
Adobe Flex SDK | =3.6 | |
Adobe Flex SDK | =4.1 | |
Adobe Flex SDK | =3.2 | |
Adobe Flex SDK | =3.3 | |
Adobe Flex SDK | =4.5 | |
Adobe Flex SDK | =3.5 | |
Adobe Flex SDK | =3.0 | |
Adobe Flex SDK | =3.4 | |
Adobe Flex SDK | =3.0.1 | |
Adobe Flex SDK | =4.5.1 | |
Adobe Flex SDK | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2461 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2011-2461, update to Adobe Flex SDK version 4.6 or later where this vulnerability has been addressed.
CVE-2011-2461 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
CVE-2011-2461 affects Adobe Flex SDK versions 3.x and 4.x before 4.6.
Yes, if your web application uses vulnerable versions of the Adobe Flex SDK, it can be exposed to XSS vulnerabilities.