'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2024-10099:ComfyUI Cross-Site Scripting Vulnerability
Severity:mid
CVE ID:CVE-2024-10099
Descripiton:
|
ComfyUI is one of the most powerful and modular diffusion model GUI and backend for individual developers of comfyanonymous. ComfyUI 0.2.2 and earlier has a cross site scripting vulnerability, which is due to the existence of a stored cross site scripting (XSS) vulnerability. An attacker can upload an HTML file containing a malicious XSS payload to cause the execution of arbitrary JavaScript code. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.