open-webui/open-webui
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*
- v0.3.8
An improper privilege management vulnerability exists in Open-WebUI version 0.3.8. The application allows an admin user to delete other administrators through the API, despite this action being restricted in the user interface. The vulnerability arises because the API endpoint for user deletion does not properly enforce privilege checks, allowing admins to remove each other arbitrarily.
Exploitation of this vulnerability allows an admin user to delete other administrators from the application.
To reproduce this vulnerability, log into the application as an admin. Then, send a DELETE request to the API endpoint for user deletion, including the UUID of the administrator to be removed and an authorization token. The request will successfully delete the specified administrator.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.