Aimeos是Aimeos开源的一个面向在线商店的开源电子商务框架。 Aimeos 2020.10.27、2021.10.21、2022.10.12、2023.10.14 和 2024.04.5 之前版本存在安全漏洞,该漏洞源于在线商店出售的数字下载内容无需有效付款即可下载。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aimeos | ai-client-html | >= 2024.04.1, < 2024.04.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-37295 | 7.2 HIGH | Aimeos Core remote code execution in web server context |
| CVE-2024-37294 | 5.5 MEDIUM | Aimeos denial of service vulnerability in SaaS and marketplace setups |
No comments yet