CVE-2024-39319

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Mar 5, 2025
CWE ID 639

Summary

CVE-2024-39319 is a vulnerability affecting the Aimeos frontend controller package, specifically versions prior to 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 of the aimeos/ai-controller-frontend. This e-commerce project component contains an insecure direct object reference, which can be exploited by attackers to disable subscriptions and reviews of other customers. The vulnerability has been addressed in subsequent versions, including 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share