Remote File Exposure in Infinite Image Browsing Extension for Stable Diffusion Web UI
CVE-2023-46315
7.5HIGH
What is CVE-2023-46315?
The Infinite Image Browsing extension for Stable Diffusion web UI has a vulnerability when Gradio authentication is activated without configuring a secret key. This flaw allows remote attackers to exploit the system to read local files by appending specific paths in the URL. This can disclose sensitive information, including environment variables and credentials, posing significant security risks.
