CVE-2024-5735
Full Path Disclosure vulnerability in AdmirorFrames Joomla!
MEDIUM
admirorframes
Description
Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.
Sévérité
6.3
Moyenne · CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Green
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.3 (v4.0) |
Produit et versions
- Produit
- admirorframes
- Corrigée dans
- 5.0
- Publiée
- 28/06/2024
- Modifiée
- 17/06/2026
- CWE
- CWE-497
Versions concernées
- AdmirorFrames — 0 – 0
- admirorframes — jusqu'à 5.0 (exclue)
Sources
- NVD CVE-2024-5735 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC