CVE-2024-39324

CVSS V2 None CVSS V3 None
Description
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue.
Overview
  • CVE ID
  • CVE-2024-39324
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-02T20:09:22.872Z
  • Last Modified Date
  • 2024-07-02T20:09:22.872Z
History
Created Old Value New Value Data Type Notes
2024-07-03 13:13:20 Added to TrackCVE