A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's browser.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Automatic1111
Automatic1111 stable-diffusion-webui |
|
| CPEs | cpe:2.3:a:automatic1111:stable-diffusion-webui:2024-07-27:*:*:*:*:*:*:* | |
| Vendors & Products |
Automatic1111
Automatic1111 stable-diffusion-webui |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's browser. | |
| Title | Stored XSS in automatic1111/stable-diffusion-webui | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:08:49.639Z
Updated: 2025-03-20T19:02:09.492Z
Reserved: 2024-12-09T17:56:35.496Z
Link: CVE-2024-12374
Updated: 2025-03-20T17:52:12.594Z
Status : Analyzed
Published: 2025-03-20T10:15:27.677
Modified: 2025-10-30T15:29:31.037
Link: CVE-2024-12374
No data.