PT-2024-19128 · Aim · Aim
Published
2024-04-10
·
Updated
2025-07-29
·
CVE-2024-2196
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
aimhubio/aim (affected versions not specified)
Description
The issue allows attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. This is due to the lack of CSRF and CORS protection in the aim dashboard. An attacker can exploit this by tricking a user into executing a malicious script that sends unauthorized requests to the aim server, leading to potential data loss and unauthorized data manipulation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aim