Vulnerability Description
Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to receive a patch.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/aimeos/aimeos-core/security/advisories/GHSA-xjm6-jfmg-qc6p
- https://github.com/aimeos/aimeos-core/security/advisories/GHSA-xjm6-jfmg-qc6p
FAQ
What is CVE-2024-37294?
CVE-2024-37294 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users sho...
How severe is CVE-2024-37294?
CVE-2024-37294 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-37294?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.