CVE-2024-5737
28.06.2024, 12:15
Script afGdStream.php inAdmirorFrames Joomla! extension doesnt specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML.This issue affects AdmirorFrames: before 5.0.
Vendor | Product | Version |
---|---|---|
admiror-design-studio | admirorframes | 𝑥 < 5.0 |
𝑥
= Vulnerable software versions
References