CVE-2024-37296

MEDIUM

Aimeos HTML client <2020.10.27-2024.04.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 51.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-841 CWE-862
Status published
Products (6)
aimeos/ai-client-html 2024.04.1 - 2024.04.5Packagist
aimeos/ai-client-html >= 2020.04.1, < 2020.10.27
aimeos/ai-client-html >= 2021.04.1, < 2021.10.21
aimeos/ai-client-html >= 2022.04.1, < 2022.10.12
aimeos/ai-client-html >= 2023.04.1, < 2023.10.14
aimeos/ai-client-html >= 2024.04.1, < 2024.04.5
Published Jun 11, 2024
Tracked Since Feb 18, 2026