open-webui/open-webui
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*
- v0.3.8
A vulnerability allowing improper access control has been identified in Open-WebUI version 0.3.8. This issue arises on the frontend admin page, where administrators are supposed to see only the chats of non-admin members. However, by altering the user_id parameter, it is possible to access the chats of any administrator, including those of other admin (owner) accounts.
Exploitation of this vulnerability allows administrators to improperly access and view chats of other administrators, including owner accounts.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.