Improper Access Control in Open-WebUI Product by Open-WebUI Vendor
CVE-2024-7043

8.1HIGH

Key Information:

Vendor
Open-webui
Vendor
CVE Published:
20 March 2025

Summary

Open-WebUI version 0.3.8 contains a vulnerability that allows attackers to bypass access control measures. This issue permits unauthorized users to view and delete files stored on the server. Specifically, the application fails to ensure that users are properly authenticated as administrators, leading to exploitation. Attackers are able to directly access endpoints that retrieve information about files uploaded by users and subsequently delete them. As a result, sensitive data may be exposed and manipulated, significantly impacting the confidentiality and integrity of stored information.

Affected Version(s)

open-webui/open-webui <= unspecified

References

CVSS V3.0

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.