CVE-2015-1773: Apache Flex

Medium severity, CVSS 4.3. EPSS: 7% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attackers to inject arbitrary web script or HTML by providing a crafted URI to JavaScript code generated by the asdoc component.

Affected products

  • Apache Flex: up to and including 4.14.0

Published 2015-04-08. Last modified 2026-06-17.