The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2168 The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.
Github GHSA Github GHSA GHSA-v4g2-cm5v-cxv7 Digital products download without proper payment status check
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T03:50:56.097Z

Reserved: 2024-06-05T20:10:46.496Z

Link: CVE-2024-37296

cve-icon Vulnrichment

Updated: 2024-06-11T18:47:32.006Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-11T15:16:09.963

Modified: 2024-11-21T09:23:33.377

Link: CVE-2024-37296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.