MEDIUM🇵🇱 Wersja polska

CVE-2024-50637

CVSS 5.4v3.1pub. 2024-11-06upd. 2025-06-24

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
  • Webkul Unopim

    APP
    Webkul
    < 0.1.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-55741HIGH8.1same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versio...

CVE-2025-55742HIGH8.0same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55743HIGH7.3same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55744MEDIUM6.9same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2024-52305MEDIUM6.5same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnera...