Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-08-01T21:18:07.021Z
Reserved: 2024-06-07T06:09:43.874Z
Link: CVE-2024-5737
Updated: 2024-08-01T21:18:07.021Z
Status : Modified
Published: 2024-06-28T12:15:11.060
Modified: 2024-11-21T09:48:15.713
Link: CVE-2024-5737
No data.
OpenCVE Enrichment
No data.
Weaknesses