CVE-2024-37296

The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-11 15:16

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37296

Mitre link : CVE-2024-37296

CVE.ORG link : CVE-2024-37296


JSON object : View

Products Affected

No product.

CWE
CWE-841

Improper Enforcement of Behavioral Workflow

CWE-862

Missing Authorization