CVE-2024-39325

EUVD-2024-2380
aimeos/ai-controller-frontend is the  Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket after the user completes a purchase. Versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
GitHub_MCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
aimeosaimeos_frontend_controller
𝑥
< 2020.10.15
aimeosaimeos_frontend_controller
2021.04.1 ≤
𝑥
< 2021.10.8
aimeosaimeos_frontend_controller
2022.04.1 ≤
𝑥
< 2022.10.8
aimeosaimeos_frontend_controller
2023.04.1 ≤
𝑥
< 2023.10.9
aimeosaimeos_frontend_controller
2024.04.1
𝑥
= Vulnerable software versions