Описание
Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.
Ссылки
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Issue Tracking
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Issue Tracking
Уязвимые конфигурации
Конфигурация 1Версия до 5.0 (исключая)
cpe:2.3:a:admiror-design-studio:admirorframes:*:*:*:*:*:joomla\!:*:*
EPSS
Процентиль: 95%
0.16107
Средний
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79
EPSS
Процентиль: 95%
0.16107
Средний
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79