CVE-2024-39319

MEDIUM

Aimeos Frontend Controller < 2020.10.15 - IDOR

Title source: rule
STIX 2.1

Description

aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.

Scores

CVSS v3 5.3
EPSS 0.0056
EPSS Percentile 68.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (3)
aimeos/ai-controller-frontend 2024.04.1 - 2024.04.2Packagist
aimeos/aimeos_frontend_controller 2024.04.1
aimeos/aimeos_frontend_controller < 2020.10.15
Published Sep 26, 2024
Tracked Since Feb 18, 2026