← voltar
CVE-2024-8017criticalCWE-79

Cross-site Scripting (XSS) in open-webui/open-webui

28Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 9epss 0.6%
probabilidade de exploração
0.6%top 56% das CVEs
exploração observada
nãonenhuma fonte reporta
An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H