CVE-2024-7035
CVSS 3.0 Score 6.9 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 352
Summary
CVE-2024-7035 is a vulnerability affecting open-webui version v0.3.8. The issue lies in the performance of sensitive actions, such as deletion and resetting, using the GET method. An attacker can exploit this Cross-Site Request Forgery (CSRF) weakness to manipulate unsuspecting users into executing damaging commands. Endpoints like /rag/api/v1/reset, /rag/api/v1/reset/db, /api/v1/memories/reset, and /rag/api/v1/reset/uploads are susceptible to this attack. The consequences of this flaw are twofold, impacting both the application's availability and integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.