aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 16:15:00 +0000
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-26T16:07:01.482Z
Updated: 2024-09-26T18:24:00.120Z
Reserved: 2024-06-21T18:15:22.262Z
Link: CVE-2024-39319
Vulnrichment
No data.
NVD
Status : Awaiting Analysis
Published: 2024-09-26T16:15:07.947
Modified: 2024-09-30T12:46:20.237
Link: CVE-2024-39319
Redhat
No data.