VYPR
Unrated severityNVD Advisory· Published Jun 28, 2024· Updated Aug 1, 2024

HTML Injection in AdmirorFrames Joomla! Extension

CVE-2024-5737

Description

Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.