CVE-2024-37296
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jun 11, 2024
Updated: Jun 13, 2024
CWE ID 841
CWE ID 862
Summary
CVE-2024-37296 is a vulnerability affecting the Aimeos HTML client, used in e-commerce projects. Before versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, this software allowed for unauthorized digital downloads, even when payments failed. As a result, customers could obtain files without completing a valid transaction. The affected versions have since been updated to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share