
Patched Adobe Flex SWF files (editor.swf, uploader.swf, uploaderSingle.swf) to fix the CVE-2011-2461 CSRF vulnerability in Magento. Replace vulnerable files with secure versions.
This CVE relates to a CSRF vulnerability in the Adobe Flex .swf files used by Magento.
You can find more information regarding the CVE here:
This repo contains patched versions of editor.swf, uploader.swf and uploaderSingle.swf.
Simply replace the files in skin/adminhtml/default/default/media/ with these.