CVE-2024-37296
MEDIUMAimeos HTML client <2020.10.27-2024.04.5 - Info Disclosure
Title source: llmDescription
The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_confirm
https://github.com/aimeos/ai-client-html/security/advisories/GHSA-v4g2-cm5v-cxv7
Patch x_refsource_misc
https://github.com/aimeos/ai-client-html/commit/12d8aad1a373bf9d350872501adec3e222164f83
Patch x_refsource_misc
https://github.com/aimeos/ai-client-html/commit/5a7249769142b3ce70959ab1fb70c7e7c251e214
Patch x_refsource_misc
https://github.com/aimeos/ai-client-html/commit/6460ffe8f4929d864164aa96c5b49eca5326d975
Patch x_refsource_misc
https://github.com/aimeos/ai-client-html/commit/7f01d2f4fbc67f5231fd84adeb835d28252b8409
Patch x_refsource_misc
https://github.com/aimeos/ai-client-html/commit/fc611ff9a57e421d0ad9d99346b561cea515c5f0
Scores
CVSS v3
5.3
EPSS
0.0028
EPSS Percentile
51.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-841
CWE-862
Status
published
Products (6)
aimeos/ai-client-html
2024.04.1 - 2024.04.5Packagist
aimeos/ai-client-html
>= 2020.04.1, < 2020.10.27
aimeos/ai-client-html
>= 2021.04.1, < 2021.10.21
aimeos/ai-client-html
>= 2022.04.1, < 2022.10.12
aimeos/ai-client-html
>= 2023.04.1, < 2023.10.14
aimeos/ai-client-html
>= 2024.04.1, < 2024.04.5
Published
Jun 11, 2024
Tracked Since
Feb 18, 2026