SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-5735

Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder.

MEDIUM 6.3EPSS 1.52%

Does this matter?

Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.

Description

Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.

CVSS 4.0
6.3 MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
1.52% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-497
Affected
admiror-design-studio/admirorframes
Source
cvd@cert.pl

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.