PT-2024-19128 · Aim · Aim

CVE-2024-2196

·

Published

2024-04-10

·

Updated

2026-07-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aimhubio/aim (affected versions not specified)
Description The issue allows attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. This is due to the lack of CSRF and CORS protection in the aim dashboard. An attacker can exploit this by tricking a user into executing a malicious script that sends unauthorized requests to the aim server, leading to potential data loss and unauthorized data manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2196
GHSA-99W2-67H8-5948
PYSEC-2026-1084

Affected Products

Aim