CVE-2024-39323: Aimeos Ai-Admin-Graphql
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue.
Affected products
- Aimeos Ai-Admin-Graphql: from 2022.04.1, before 2022.10.10 (fixed in 2022.10.10); from 2023.04.1, before 2023.10.6 (fixed in 2023.10.6); from 2024.04.1, before 2024.04.6 (fixed in 2024.04.6)
Published 2024-07-02. Last modified 2026-06-17.