MEDIUM🇵🇱 Wersja polska

CVE-2024-52305

CVSS 6.5v3.1pub. 2024-11-13upd. 2024-11-19

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • Webkul Unopim

    APP
    Webkul
    < 0.1.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-55741HIGH8.1same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versio...

CVE-2025-55742HIGH8.0same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55743HIGH7.3same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55744MEDIUM6.9same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2024-50637MEDIUM5.4same product

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows at...