Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-8863", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2024-09-14T05:49:44.253Z", "datePublished": "2024-09-14T23:00:05.339Z", "dateUpdated": "2024-09-16T14:13:21.333Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2024-09-14T23:00:05.339Z"}, "title": "aimhubio aim Text Explorer textbox.tsx dangerouslySetInnerHTML cross site scripting", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-79", "lang": "en", "description": "Cross Site Scripting"}]}], "affected": [{"vendor": "aimhubio", "product": "aim", "versions": [{"version": "3.0", "status": "affected"}, {"version": "3.1", "status": "affected"}, {"version": "3.2", "status": "affected"}, {"version": "3.3", "status": "affected"}, {"version": "3.4", "status": "affected"}, {"version": "3.5", "status": "affected"}, {"version": "3.6", "status": "affected"}, {"version": "3.7", "status": "affected"}, {"version": "3.8", "status": "affected"}, {"version": "3.9", "status": "affected"}, {"version": "3.10", "status": "affected"}, {"version": "3.11", "status": "affected"}, {"version": "3.12", "status": "affected"}, {"version": "3.13", "status": "affected"}, {"version": "3.14", "status": "affected"}, {"version": "3.15", "status": "affected"}, {"version": "3.16", "status": "affected"}, {"version": "3.17", "status": "affected"}, {"version": "3.18", "status": "affected"}, {"version": "3.19", "status": "affected"}, {"version": "3.20", "status": "affected"}, {"version": "3.21", "status": "affected"}, {"version": "3.22", "status": "affected"}, {"version": "3.23", "status": "affected"}, {"version": "3.24", "status": "affected"}], "modules": ["Text Explorer"]}], "descriptions": [{"lang": "en", "value": "A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}, {"lang": "de", "value": "Es wurde eine Schwachstelle in aimhubio aim bis 3.24 gefunden. Sie wurde als problematisch eingestuft. Es betrifft die Funktion dangerouslySetInnerHTML der Datei textbox.tsx der Komponente Text Explorer. Durch die Manipulation des Arguments query mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."}], "metrics": [{"cvssV4_0": {"version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N", "baseSeverity": "MEDIUM"}}, {"cvssV3_1": {"version": "3.1", "baseScore": 3.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N", "baseSeverity": "LOW"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 3.5, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N", "baseSeverity": "LOW"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 4, "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N"}}], "timeline": [{"time": "2024-09-14T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2024-09-14T02:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2024-09-14T07:54:47.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "aftersnow (VulDB User)", "type": "reporter"}], "references": [{"url": "https://vuldb.com/?id.277500", "name": "VDB-277500 | aimhubio aim Text Explorer textbox.tsx dangerouslySetInnerHTML cross site scripting", "tags": ["vdb-entry", "technical-description"]}, {"url": "https://vuldb.com/?ctiid.277500", "name": "VDB-277500 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": ["signature", "permissions-required"]}, {"url": "https://vuldb.com/?submit.403203", "name": "Submit #403203 | aimhubio aim <=3.24 Stored XSS", "tags": ["third-party-advisory"]}, {"url": "https://rumbling-slice-eb0.notion.site/Stored-XSS-through-TEXT-EXPLORER-in-aimhubio-aim-d0f07b7194724950a673498546d80d43?pvs=4", "tags": ["exploit"]}]}, "adp": [{"affected": [{"vendor": "aimhubio", "product": "aim", "cpes": ["cpe:2.3:a:aimhubio:aim:3.0.0:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "3.0.0", "status": "affected", "lessThanOrEqual": "3.2.4", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-09-16T14:12:24.322305Z", "id": "CVE-2024-8863", "options": [{"Exploitation": "poc"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-16T14:13:21.333Z"}}]}}