open-webui/open-webui
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*
- <= 0.3.8
A cross-site scripting (XSS) vulnerability has been identified in Open-WebUI versions through 0.3.8. The issue arises in the tooltip HTML construction function, allowing attackers to execute actions with the victim's privileges. This could include stealing chat history, deleting chats, and escalating their account to admin status if the victim is an admin.
Exploitation of this vulnerability allows for cross-site scripting, with potential consequences including unauthorized actions taken on behalf of the victim, such as accessing or deleting chat history and manipulating account privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.