CVE-2024-39322

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
GitHub_MCNA
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
aimeos_projectai-controller-frontend
𝑥
< 2020.10.13
aimeos_projectai-controller-frontend
2021.04.1 ≤
𝑥
< 2021.10.6
aimeos_projectai-controller-frontend
2022.04.1 ≤
𝑥
< 2022.10.3
aimeos_projectai-controller-frontend
2023.04.1 ≤
𝑥
< 2023.10.4
aimeos_projectai-controller-frontend
2024.04.1
𝑥
= Vulnerable software versions