CVE-2024-8101
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-8101 is a stored cross-site scripting (XSS) vulnerability affecting the Text Explorer component of aimhubio/aim version 3.23.0. The issue stems from the use of `dangerouslySetInnerHTML` without proper sanitization, making it susceptible to malicious JavaScript injection. During the training process, an attacker can introduce malicious HTML content, which is then rendered unsanitized in the Text Explorer, potentially leading to arbitrary code execution and data theft. This vulnerability poses a significant security risk and requires immediate remediation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aim