Metrics
Affected Vendors & Products
Mon, 16 Jun 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 15 Jun 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /upload/image of the component Incomplete Fix CVE-2024-10099. The manipulation of the argument image leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | comfyanonymous comfyui Incomplete Fix CVE-2024-10099 image cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-15T17:31:05.460Z
Updated: 2025-06-16T16:33:21.100Z
Reserved: 2025-06-14T23:08:26.688Z
Link: CVE-2025-6092

Updated: 2025-06-16T16:33:17.383Z

Status : Awaiting Analysis
Published: 2025-06-15T18:15:19.037
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-6092

No data.