Vulnerability Description
A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user management actions such as deleting, editing, or adding users. The vulnerability can also be exploited by authenticated users with low privileges, leading to the same unresponsive state in the Admin panel.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | 0.3.8 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/ba62d093-ab27-48fa-9c53-0602c8cdc48aExploitThird Party Advisory
FAQ
What is CVE-2024-7036?
CVE-2024-7036 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prev...
How severe is CVE-2024-7036?
CVE-2024-7036 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7036?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.