Aimeos是Aimeos开源的一个面向在线商店的开源电子商务框架。 Aimeos 2024.04.5 之前版本存在安全漏洞,该漏洞源于具有管理权限的用户可以上传看起来像图像但包含 PHP 代码的文件,这些文件可以在 Web 服务器的环境中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aimeos | aimeos-core | >= 2024.04.1, < 2024.04.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-37294 | 5.5 MEDIUM | Aimeos denial of service vulnerability in SaaS and marketplace setups |
| CVE-2024-37296 | 5.3 MEDIUM | Aimeos HTML client vulnerable to digital products download without proper payment status c |
No comments yet