First published: Fri Jun 28 2024(Updated: )
Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.
Credit: cvd@cert.pl
Affected Software | Affected Version | How to fix |
---|---|---|
Admiror Design Studio | <5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5737 is a medium severity vulnerability due to its potential to allow HTML injection through image data.
To fix CVE-2024-5737, update the AdmirorFrames Joomla! extension to version 5.0 or later.
CVE-2024-5737 affects versions of the AdmirorFrames extension prior to 5.0 on Joomla! platforms.
An attacker exploiting CVE-2024-5737 can embed malicious HTML tags in image data that may be executed by web browsers.
As of now, there have been no widely reported active exploits for CVE-2024-5737, but it remains a potential threat.