CVE-2024-7760 is a critical Cross-Site Request Forgery (CSRF) vulnerability affecting aimhubio/aim version 3.22.0, specifically within its tracking server due to overly permissive CORS settings. This allows cross-origin requests from any source, enabling CSRF attacks against all tracking server endpoints. With a CVSS score of 9.6 (CRITICAL), the vulnerability is easily exploitable over the network with low complexity and user interaction, potentially leading to remote code execution, denial of service, or arbitrary file read/write. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.22.0CPE matchmatch criteria | cpe:2.3:a:aimstack:aim:3.22.0:*:*:*:*:python:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.