A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lollms
Lollms lollms Web Ui |
|
CPEs | cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lollms
Lollms lollms Web Ui |
|
Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Parisneo
Parisneo lollms-webui |
|
CPEs | cpe:2.3:a:parisneo:lollms-webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Parisneo
Parisneo lollms-webui |
|
Metrics |
ssvc
|
Tue, 29 Oct 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash. | |
Title | CSRF Vulnerability in parisneo/lollms-webui | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-29T12:50:20.748Z
Updated: 2024-10-29T18:10:09.460Z
Reserved: 2024-07-10T20:16:52.200Z
Link: CVE-2024-6673
Vulnrichment
Updated: 2024-10-29T18:10:05.955Z
NVD
Status : Analyzed
Published: 2024-10-29T13:15:08.040
Modified: 2024-11-01T20:37:28.277
Link: CVE-2024-6673
Redhat
No data.