CVE-2024-39322: Aimeos Project Ai-Controller-Frontend
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.
Affected products
- Aimeos Project Ai-Controller-Frontend: before 2020.10.13 (fixed in 2020.10.13); from 2021.04.1, before 2021.10.6 (fixed in 2021.10.6); from 2022.04.1, before 2022.10.3 (fixed in 2022.10.3); from 2023.04.1, before 2023.10.4 (fixed in 2023.10.4); version 2024.04.1 only
Published 2024-07-02. Last modified 2026-06-17.