CVE-2024-7036
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-7036 is a newly identified vulnerability in open-webui/open-webui version 0.3.8. An attacker, whether unauthenticated or with low privileges, can exploit this issue by submitting excessively large text in the 'name' field during sign-up. Consequences of this attack include an unresponsive Admin panel, preventing essential user management actions such as deletion, editing, or addition of users. This vulnerability poses a significant risk to the functionality of user management systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.