Логотип exploitDog
bind:CVE-2024-2196
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2196

Количество 2

Количество 2

nvd логотип

CVE-2024-2196

почти 2 года назад

aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. The vulnerability stems from the lack of CSRF and CORS protection in the aim dashboard. An attacker can exploit this by tricking a user into executing a malicious script that sends unauthorized requests to the aim server, leading to potential data loss and unauthorized data manipulation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-99w2-67h8-5948

почти 2 года назад

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-2196

aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. The vulnerability stems from the lack of CSRF and CORS protection in the aim dashboard. An attacker can exploit this by tricking a user into executing a malicious script that sends unauthorized requests to the aim server, leading to potential data loss and unauthorized data manipulation.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-99w2-67h8-5948

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

CVSS3: 8.8
1%
Низкий
почти 2 года назад

Уязвимостей на страницу