Description
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21716 | A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component. |
References
History
Thu, 17 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aliconnect
Aliconnect software Development Kit |
|
| CPEs | cpe:2.3:a:aliconnect:software_development_kit:0.0.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Aliconnect
Aliconnect software Development Kit |
Tue, 01 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1321 | |
| Metrics |
cvssV3_1
|
Fri, 28 Mar 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-01T19:02:19.816Z
Reserved: 2024-01-25T00:00:00.000Z
Link: CVE-2024-24292
Updated: 2025-04-01T19:02:11.950Z
Status : Analyzed
Published: 2025-03-28T21:15:15.833
Modified: 2025-04-17T13:56:10.917
Link: CVE-2024-24292
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD