open-webui/open-webui
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*
- 0.3.8
A vulnerability in Open-WebUI version 0.3.8 allows attackers to access admin details due to improper access control. The application fails to verify if the requester is an administrator, enabling direct calls to the '/api/v1/auths/admin/details' endpoint to retrieve information about the first admin (owner).
Exploitation of this vulnerability allows unauthorized users to view sensitive admin information, including email and name details.
To reproduce this vulnerability, send a GET request to the '/api/v1/auths/admin/details' endpoint. Include an Authorization header with a valid bearer token. The request can be made using tools like cURL or Postman.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.