An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/auths/admin/details interface to retrieve the first admin (owner) details.
| Software | From | Fixed in |
|---|---|---|
open-webui
|
- | 0.3.8.x |
| openwebui / open_webui | 0.3.8 | 0.3.8.x |