Back

CVE-2011-3642

CRITICAL

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

Published: Feb 8, 2020 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
flowplayer flowplayer_flash * ≥ 3.2.7
flowplayer flowplayer_flash * ≥ 3.2.7

GitHub Security Advisory GHSA-5pqr-mwfx-8q8w

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the...

Risk Scores

CVSS Score 9.6 / 10
EPSS Score 8.75%

Top 5% most likely to be exploited

Threat Score 41 / 100

Data Sources

NVD EPSS GitHub