Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6957 | aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write. |
Github GHSA |
GHSA-38r9-3j52-h92v | Aim vulnerable to Cross-Site Request Forgery |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimstack
Aimstack aim |
|
| CPEs | cpe:2.3:a:aimstack:aim:3.22.0:*:*:*:*:python:*:* | |
| Vendors & Products |
Aimstack
Aimstack aim |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write. | |
| Title | CSRF in aimhubio/aim | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:58:57.731Z
Reserved: 2024-08-13T17:56:46.594Z
Link: CVE-2024-7760
Updated: 2025-03-20T17:51:48.446Z
Status : Analyzed
Published: 2025-03-20T10:15:36.590
Modified: 2025-07-21T19:47:31.643
Link: CVE-2024-7760
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA