MEDIUM🇵🇱 Wersja polska

CVE-2025-55744

CVSS 6.9v4.0pub. 2025-08-21upd. 2025-08-22

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Webkul Unopim

    APP
    Webkul
    < 0.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-55741HIGH8.1same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versio...

CVE-2025-55742HIGH8.0same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2025-55743HIGH7.3same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0....

CVE-2024-52305MEDIUM6.5same product

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnera...

CVE-2024-50637MEDIUM5.4same product

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows at...