Lucene search

K
nvd[email protected]NVD:CVE-2024-5737
HistoryJun 28, 2024 - 12:15 p.m.

CVE-2024-5737

2024-06-2812:15:11
CWE-79
web.nvd.nist.gov
2
html injection
admirorframes
joomla extension
cve-2024-5737

0.0004 Low

EPSS

Percentile

15.7%

Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.

0.0004 Low

EPSS

Percentile

15.7%

Related for NVD:CVE-2024-5737