We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6673

CSRF Vulnerability in parisneo/lollms-webui



Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.

Reserved 2024-07-10 | Published 2024-10-29 | Updated 2024-10-29 | Assigner @huntr_ai


MEDIUM: 4.4CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Any version before 9.9
affected

References

huntr.com/bounties/a38f9a7d-b357-427d-adac-f9654d8c0e3c

github.com/...ommit/c1bb1ad19752aa7541675b398495eaf98fd589f1

cve.org (CVE-2024-6673)

nvd.nist.gov (CVE-2024-6673)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-6673

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.