aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2868 | IDOR vulnerability in account profile page |
Github GHSA |
GHSA-rw3j-574h-mrcq | IDOR vulnerability in account profile page |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 26 Sep 2024 16:15:00 +0000
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-26T18:24:00.120Z
Reserved: 2024-06-21T18:15:22.262Z
Link: CVE-2024-39319
No data.
Status : Awaiting Analysis
Published: 2024-09-26T16:15:07.947
Modified: 2024-09-30T12:46:20.237
Link: CVE-2024-39319
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA