CVE-2011-3642 is a critical cross-site scripting (XSS) vulnerability affecting Flowplayer Flash versions 3.2.7 through 3.2.16, as integrated into TYPO3's News system and Mahara. This flaw allows remote attackers to inject arbitrary web script or HTML by manipulating the plugin configuration directive within an external domain plugin reference. With a CVSS score of 9.6, it represents a high-impact threat, enabling complete compromise of confidentiality, integrity, and availability through a low-complexity network attack requiring user interaction. While not listed on CISA's KEV catalog, an exploit (EDB-35941) is publicly available, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.7, <= 3.2.16CPE matchmatch criteria | cpe:2.3:a:flowplayer:flowplayer_flash:*:*:*:*:*:mahara:*:* | ||
>= 3.2.7, <= 3.2.16CPE matchmatch criteria | cpe:2.3:a:flowplayer:flowplayer_flash:*:*:*:*:*:typo3:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.