Vulnerability Description
In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is possible to view the chats of any administrator, including those of other admin (owner) accounts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | 0.3.8 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1ExploitThird Party Advisory
FAQ
What is CVE-2024-7040?
CVE-2024-7040 is a vulnerability with a CVSS score of 4.9 (MEDIUM). In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. Howe...
How severe is CVE-2024-7040?
CVE-2024-7040 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7040?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.