Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-39325

19
FAUCET Score

CVE-2024-39325 is a medium-severity vulnerability affecting the aimeos/ai-controller-frontend, an Aimeos frontend controller, in versions prior to 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15. The flaw allows a user's basket payment status to remain unreset after a completed purchase, potentially leading to incorrect order processing. With a CVSS score of 5.3, this vulnerability has a low attack complexity and does not require user interaction or privileges, but its impact is limited to integrity (L) with no confidentiality or availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2020.10.15CPE matchmatch criteria
cpe:2.3:a:aimeos:aimeos_frontend_controller:*:*:*:*:*:*:*:*
>= 2021.04.1, < 2021.10.8CPE matchmatch criteria
cpe:2.3:a:aimeos:aimeos_frontend_controller:*:*:*:*:*:*:*:*
>= 2022.04.1, < 2022.10.8CPE matchmatch criteria
cpe:2.3:a:aimeos:aimeos_frontend_controller:*:*:*:*:*:*:*:*
>= 2023.04.1, < 2023.10.9CPE matchmatch criteria
cpe:2.3:a:aimeos:aimeos_frontend_controller:*:*:*:*:*:*:*:*
2024.04.1CPE matchmatch criteria
cpe:2.3:a:aimeos:aimeos_frontend_controller:2024.04.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 22nd percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

composerpatch availablevia ghsa
Product: aimeos/ai-controller-frontendFixed in: 2023.10.9
composerpatch availablevia ghsa
Product: aimeos/ai-controller-frontendFixed in: 2022.10.8
composerpatch availablevia ghsa
Product: aimeos/ai-controller-frontendFixed in: 2021.10.8
composerpatch availablevia ghsa
Product: aimeos/ai-controller-frontendFixed in: 2020.10.15
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-m9gv-6p22-qgmjmedium

ai-controller-frontend payment status in basket isn't reset

Jul 5, 2024

References

github.com / aimeos/ai-controller-frontend/commit/16b8837d2466e3665b3c826ce87934b01a847268
Patch
github.com / aimeos/ai-controller-frontend/commit/24a57001e56759d1582d2a0080fc1ca3ba328630
Patch
github.com / aimeos/ai-controller-frontend/commit/28549808e0f6432a34cd3fb95556deeb86ca276d
Patch
github.com / aimeos/ai-controller-frontend/commit/b1960c0b6e5ee93111a5360c9ce949b3e7528cf7
Patch
github.com / aimeos/ai-controller-frontend/commit/dafa072783bb692f111ed092d9d2932c113eb855
Patch
github.com / aimeos/ai-controller-frontend/security/advisories/GHSA-m9gv-6p22-qgmj
Vendor Advisory