PT-2024-37790 · Unknown · Lollms-Webui

Published

2024-10-29

·

Updated

2024-11-02

·

CVE-2024-6673

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lollms-webui versions v9.9 through the latest
Description A Cross-Site Request Forgery (CSRF) issue exists in the "install comfyui" endpoint of the lollms comfyui.py file. This endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.
Recommendations For versions v9.9 through the latest, consider disabling the install comfyui endpoint until a patch is available to prevent potential CSRF attacks. Restrict access to the lollms comfyui.py file to minimize the risk of exploitation. Avoid using the GET method for the "install comfyui" endpoint without proper validation and authentication mechanisms in place.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-6673

Affected Products

Lollms-Webui