Security Advisory

CVE-2024-37296

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-06-11 14:43:39
Last updated 2024-08-02 03:50:56
Assigner GitHub_M
State PUBLISHED

Description

The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didnt succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.