CVE-2024-39319 - Aimeos ai-Controller Frontend Insecure Direct Object Reference Vulnerability

3 weeks ago 7
ARTICLE AD BOX
CVE ID : CVE-2024-39319
Published : Sept. 26, 2024, 4:15 p.m. | 24 minutes ago
Description : aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article