CVE-2024-6673

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*

History

01 Nov 2024, 20:37

Type Values Removed Values Added
References () https://github.com/parisneo/lollms-webui/commit/c1bb1ad19752aa7541675b398495eaf98fd589f1 - () https://github.com/parisneo/lollms-webui/commit/c1bb1ad19752aa7541675b398495eaf98fd589f1 - Patch
References () https://huntr.com/bounties/a38f9a7d-b357-427d-adac-f9654d8c0e3c - () https://huntr.com/bounties/a38f9a7d-b357-427d-adac-f9654d8c0e3c - Exploit, Third Party Advisory
CPE cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 6.5
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Request Forgery (CSRF) en el endpoint `install_comfyui` del archivo `lollms_comfyui.py` en el repositorio parisneo/lollms-webui, versiones v9.9 hasta la más reciente. El endpoint utiliza el método GET sin requerir un ID de cliente, lo que permite a un atacante engañar a una víctima para que instale ComfyUI. Si el dispositivo de la víctima no tiene suficiente capacidad, esto puede provocar un bloqueo.
First Time Lollms lollms Web Ui
Lollms

29 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 13:15

Updated : 2024-11-01 20:37


NVD link : CVE-2024-6673

Mitre link : CVE-2024-6673

CVE.ORG link : CVE-2024-6673


JSON object : View

Products Affected

lollms

  • lollms_web_ui
CWE
CWE-352

Cross-Site Request Forgery (CSRF)