CVE-2024-39319
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Mar 5, 2025
CWE ID 639
Summary
CVE-2024-39319 is a vulnerability affecting the Aimeos frontend controller package, specifically versions prior to 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 of the aimeos/ai-controller-frontend. This e-commerce project component contains an insecure direct object reference, which can be exploited by attackers to disable subscriptions and reviews of other customers. The vulnerability has been addressed in subsequent versions, including 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.