CVE-2024-6578

CVSS V2 None CVSS V3 None
Description
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the `dangerouslySetInnerHTML` function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by injecting malicious scripts into the logs, which will be executed when a user views the logs-tab.
Overview
  • CVE ID
  • CVE-2024-6578
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-29T18:37:16.820Z
  • Last Modified Date
  • 2024-07-29T18:47:14.318Z
References
History
Created Old Value New Value Data Type Notes
2024-07-30 13:23:05 Added to TrackCVE