216.73.216.233

CVE-2024-8863

· Published 14/09/2024 23:15 · Modified 20/09/2024 15:43

Labels: CVE-2024-8863 2024-09-14CVE-2024-8863CWE-79[email protected]

Essential information

Published
14/09/2024 23:15
Modified
20/09/2024 15:43
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
aimstack / aim cpe:2.3:a:aimstack:aim:*:*:*:*:*:*:*:*

References