CVE-2024-39322

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.
Configurations

No configuration.

History

No history.

Information

Published : 2024-07-02 21:15

Updated : 2024-07-03 12:53


NVD link : CVE-2024-39322

Mitre link : CVE-2024-39322

CVE.ORG link : CVE-2024-39322


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization