We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-39325

aimeos/ai-controller-frontend doesn't reset payment status in basket



AssignerGitHub_M
Reserved2024-06-21
Published2024-07-02
Updated2024-08-02

Description

aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket after the user completes a purchase. Versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue.



MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-841: Improper Enforcement of Behavioral Workflow

Product status

= 2024.04.1
affected

>= 2023.04.1, < 2023.10.9
affected

>= 2022.04.1, < 2022.10.8
affected

>= 2021.04.1, < 2021.10.8
affected

< 2020.10.15
affected

References

https://github.com/aimeos/ai-controller-frontend/security/advisories/GHSA-m9gv-6p22-qgmj

https://github.com/aimeos/ai-controller-frontend/commit/16b8837d2466e3665b3c826ce87934b01a847268

https://github.com/aimeos/ai-controller-frontend/commit/24a57001e56759d1582d2a0080fc1ca3ba328630

https://github.com/aimeos/ai-controller-frontend/commit/28549808e0f6432a34cd3fb95556deeb86ca276d

https://github.com/aimeos/ai-controller-frontend/commit/b1960c0b6e5ee93111a5360c9ce949b3e7528cf7

https://github.com/aimeos/ai-controller-frontend/commit/dafa072783bb692f111ed092d9d2932c113eb855

cve.org CVE-2024-39325

nvd.nist.gov CVE-2024-39325

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-39325
Subscribe to our newsletter to learn more about our work.