CVE-2024-7045

CVSS 3.0 Score 4.3 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 1100

Summary

CVE-2024-7045 is a vulnerability affecting open-webui version v0.3.8. It involves improper access control, allowing attackers to bypass authentication and view any prompts created by administrators. The application fails to verify the attacker's administrator status, enabling them to access the /api/v1/prompts/ interface and retrieve all prompt ID values. Furthermore, attackers can exploit the /api/v1/prompts/command/{command_id} interface to obtain arbitrary prompt information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share