CVE-2024-5737: HTML Injection in AdmirorFrames Joomla! Extension
Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5737?
CVE-2024-5737 is a medium severity vulnerability due to its potential to allow HTML injection through image data.
How do I fix CVE-2024-5737?
To fix CVE-2024-5737, update the AdmirorFrames Joomla! extension to version 5.0 or later.
What systems are affected by CVE-2024-5737?
CVE-2024-5737 affects versions of the AdmirorFrames extension prior to 5.0 on Joomla! platforms.
What can an attacker do with CVE-2024-5737?
An attacker exploiting CVE-2024-5737 can embed malicious HTML tags in image data that may be executed by web browsers.
Is CVE-2024-5737 being actively exploited?
As of now, there have been no widely reported active exploits for CVE-2024-5737, but it remains a potential threat.