CVE-2024-39319

EUVD-2024-2868
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
aimeosaimeos_frontend_controller
𝑥
< 2020.10.15
aimeosaimeos_frontend_controller
2021.04.1 ≤
𝑥
< 2021.10.8
aimeosaimeos_frontend_controller
2022.04.1 ≤
𝑥
< 2022.10.8
aimeosaimeos_frontend_controller
2023.04.1 ≤
𝑥
< 2023.10.9
aimeosaimeos_frontend_controller
2024.04.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
aimeos_projectai-controller-frontend
2023.04.1 ≤
𝑥
< 2023.10.9
ADP
aimeos_projectai-controller-frontend
2022.04.1 ≤
𝑥
< 2022.10.8
ADP
aimeos_projectai-controller-frontend
2021.04.1 ≤
𝑥
< 2021.10.8
ADP
aimeos_projectai-controller-frontend
𝑥
< 2020.10.15
ADP