Skip to main content

Privilege Context Switching Error

CVE-2024-47173

Severity Medium
Score 5.5/10

Summary

Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface versions from 2024.04.1 through 2024.07.1 are affected by a potential Denial of Service attack.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • HIGH
  • NONE
  • HIGH

CWE-270 - Privilege Context Switching Error

The software does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

References

Advisory Timeline

  • Published