CVE-2024-5736
SSRF in AdmirorFrames Joomla! Extension
Severity Score
8.2
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.
Vulnerabilidad de Server Side Request Forgery (SSRF) en AdmirorFrames Joomla! La extensión en el script afGdStream.php permite acceder a archivos locales o páginas del servidor disponibles solo desde localhost. Este problema afecta a AdmirorFrames: anteriores a 5.0.
*Credits:
Marcin Wyczechowski [AFINE Team], Michał Majchrowicz [AFINE Team]
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-06-07 CVE Reserved
- 2024-06-28 CVE Published
- 2024-07-04 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
- CAPEC-37: Retrieve Embedded Sensitive Data
References (5)
URL | Tag | Source |
---|---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-5735 | Third Party Advisory | |
https://cert.pl/posts/2024/06/CVE-2024-5735 | Third Party Advisory | |
https://github.com/vasiljevski/admirorframes/issues/3 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://github.com/afine-com/CVE-2024-5736 | 2024-08-01 | |
https://github.com/sectroyer/CVEs/tree/main/CVE-2024-5736 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Admiror-design-studio Search vendor "Admiror-design-studio" | Admirorframes Search vendor "Admiror-design-studio" for product "Admirorframes" | < 5.0 Search vendor "Admiror-design-studio" for product "Admirorframes" and version " < 5.0" | joomla\! |
Affected
|