Vulnerability in Aimeos HTML client allows unauthorized downloads
CVE-2024-37296

5.3MEDIUM

Key Information:

Vendor
Aimeos
Status
Ai-client-html
Vendor
CVE Published:
11 June 2024

Summary

The Aimeos HTML client, utilized for building e-commerce projects, presents a security vulnerability that enables digital downloads to be accessed without appropriate payment validation. This flaw affects versions from 2020.04.1 up to multiple releases leading to 2024.04.4. Users can exploit this vulnerability to download digital products even when payment transactions have failed, potentially leading to significant revenue loss for online shop owners. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 have been released to address this issue effectively.

Affected Version(s)

ai-client-html >= 2024.04.1, < 2024.04.5 < 2024.04.1, 2024.04.5

ai-client-html >= 2023.04.1, < 2023.10.14 < 2023.04.1, 2023.10.14

ai-client-html >= 2022.04.1, < 2022.10.12 < 2022.04.1, 2022.10.12

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.