open-webui/open-webui
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*
- 0.3.8
A denial-of-service vulnerability has been identified in Open-WebUI version 0.3.8. The issue allows an unauthenticated attacker to disrupt the Admin panel by entering excessively large text in the 'name' field during the sign-up process. This overloads the system, causing the Admin panel to become unresponsive and hindering administrators from managing users effectively, including actions like deleting, editing, or adding users. Additionally, authenticated users with low privileges can exploit this vulnerability to achieve the same disruptive effect in the Admin panel.
Exploitation of this vulnerability causes the Admin panel to freeze, disrupting user management tasks such as adding, editing, or deleting users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.