Insecure Direct Object Reference Fixes Disable Subscriptions and Reviews Vulnerability
CVE-2024-39319
What is CVE-2024-39319?
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ai-controller-frontend = 2024.04.1 = 2024.04.1
ai-controller-frontend >= 2023.04.1, < 2023.10.9 < 2023.04.1, 2023.10.9
ai-controller-frontend >= 2022.04.1, < 2022.10.8 < 2022.04.1, 2022.10.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
