VYPR
Medium severity6.1NVD Advisory· Published May 14, 2021· Updated Jun 17, 2026

CVE-2021-32054

CVE-2021-32054

Description

Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a victim's web browser.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Fire.ly/Spark2 versions
    cpe:2.3:a:fire.ly:spark:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fire.ly:spark:*:*:*:*:*:*:*:*range: <=1.5.4
    • (no CPE)range: <1.5.5-r4
  • Firely/Incendi/Sparkdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.