← Back

CVE-2024-52305

nvd nist
Published: Nov 13, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

Affected (1)

Products: Webkul: Unopim
1 product
Unopim
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.1.5

References (2)

Source: security-advisories@github.com
ExploitThird Party Advisory

Timeline

No history available yet.