Логотип exploitDog
bind:CVE-2024-7760
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-7760

Количество 2

Количество 2

nvd логотип

CVE-2024-7760

11 месяцев назад

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-38r9-3j52-h92v

11 месяцев назад

Aim vulnerable to Cross-Site Request Forgery

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-7760

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.

CVSS3: 9.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-38r9-3j52-h92v

Aim vulnerable to Cross-Site Request Forgery

CVSS3: 7.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу