Vulnerability in Aimeos HTML client allows unauthorized downloads
CVE-2024-37296
What is CVE-2024-37296?
The Aimeos HTML client, utilized for building e-commerce projects, presents a security vulnerability that enables digital downloads to be accessed without appropriate payment validation. This flaw affects versions from 2020.04.1 up to multiple releases leading to 2024.04.4. Users can exploit this vulnerability to download digital products even when payment transactions have failed, potentially leading to significant revenue loss for online shop owners. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 have been released to address this issue effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ai-client-html >= 2024.04.1, < 2024.04.5 < 2024.04.1, 2024.04.5
ai-client-html >= 2023.04.1, < 2023.10.14 < 2023.04.1, 2023.10.14
ai-client-html >= 2022.04.1, < 2022.10.12 < 2022.04.1, 2022.10.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
