Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-5735

June 28, 2024, 1:38 p.m.

Product(s) Impacted

AdmirorFrames Joomla! extension

  • before 5.0

Description

Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.

Weaknesses

CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

CWE ID: 497

Date

Published: June 28, 2024, 12:15 p.m.

Last Modified: June 28, 2024, 1:38 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

cvd@cert.pl

References