Stable Diffusion WebUI 在 1.10.1 及更早版本中存在一个凭证泄露漏洞,位于 端点。该端点会返回解析后的命令行参数,其中包含以明文形式呈现的 和 值。未经身份验证的攻击者可以访问该端点,获取已配置的用户名和密码,并利用这些凭证进行身份验证,从而接入并访问该应用程序界面。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AUTOMATIC1111 | stable-diffusion-webui | ≤ 1.10.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AUTOMATIC1111 | stable-diffusion-webui | 0 ~ 1.10.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet