We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-39325

aimeos/ai-controller-frontend doesn't reset payment status in basket



Description

aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket after the user completes a purchase. Versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.

Reserved 2024-06-21 | Published 2024-07-02 | Updated 2024-08-02 | Assigner GitHub_M


MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-841: Improper Enforcement of Behavioral Workflow

Product status

= 2024.04.1
affected

>= 2023.04.1, < 2023.10.9
affected

>= 2022.04.1, < 2022.10.8
affected

>= 2021.04.1, < 2021.10.8
affected

< 2020.10.15
affected

References

github.com/...ontend/security/advisories/GHSA-m9gv-6p22-qgmj

github.com/...ommit/16b8837d2466e3665b3c826ce87934b01a847268

github.com/...ommit/24a57001e56759d1582d2a0080fc1ca3ba328630

github.com/...ommit/28549808e0f6432a34cd3fb95556deeb86ca276d

github.com/...ommit/b1960c0b6e5ee93111a5360c9ce949b3e7528cf7

github.com/...ommit/dafa072783bb692f111ed092d9d2932c113eb855

cve.org (CVE-2024-39325)

nvd.nist.gov (CVE-2024-39325)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-39325

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.