HIGH🇵🇱 Wersja polska

CVE-2025-55741

CVSS 8.1v3.1pub. 2025-08-22upd. 2025-08-25

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these users can bypass intended access controls by issuing requests to the mass-delete endpoint, allowing them to delete products without proper authorization. This vulnerability allows unauthorized product deletion, leading to potential data loss and business disruption. The issue is fixed in version 0.3.1. No known workarounds exist.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
  • Webkul Unopim

    APP
    Webkul
    < 0.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-55742HIGH8.0same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55743HIGH7.3same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55744MEDIUM6.9same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2024-52305MEDIUM6.5same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnera...

CVE-2024-50637MEDIUM5.4same product

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows at...