← Back

CVE-2024-7760

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 6.0
Source: NVD

Description

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.

Affected (1)

Products: Aimstack: Aim
1 product
Aim
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.22.0

References (1)

Source: security@huntr.dev
ExploitThird Party Advisory

Timeline

No history available yet.