CVE-2011-2461 is a cross-site scripting (XSS) vulnerability affecting Adobe Flex SDK versions 3.x and 4.x before 4.6. It allows remote attackers to inject arbitrary web script or HTML by exploiting how modules are loaded from different domains. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and partial impact on integrity, with no impact on confidentiality or availability. While not listed on the KEV catalog, there is some community discussion and media coverage, including a mention of exploiting it on Google.com, though no public exploit code is readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:adobe:flex_sdk:3.0:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:flex_sdk:3.0.1:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:adobe:flex_sdk:3.1:*:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:a:adobe:flex_sdk:3.2:*:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:a:adobe:flex_sdk:3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.