CVE-2024-37296: Aimeos Ai-Client-Html
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.
Affected products
- Aimeos Ai-Client-Html: from 2024.04.1, before 2024.04.5 (fixed in 2024.04.5); from 2023.04.1, before 2023.10.14 (fixed in 2023.10.14); from 2022.04.1, before 2022.10.12 (fixed in 2022.10.12); from 2021.04.1, before 2021.10.21 (fixed in 2021.10.21); from 2020.04.1, before 2020.10.27 (fixed in 2020.10.27)
Published 2024-06-11. Last modified 2026-06-17.