unopim/unopim
UnoPIM is a free and open-source Product Information Management (PIM) solution built on Laravel to manage, enrich, and scale product data beyond 10 million products.
Activity
- Latest release
- 17h ago
- Total releases
- 28
- Cadence
- ~12 days
- Last 12 months
- 16
Reach
- Stars
- 10.8k
Details
- License
- MIT
- First release
- Jul 29, 2024
| Version | Released | |
|---|---|---|
v3.0.0
major
|
v3.0.0
major
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.1.6
patch
|
v2.1.6
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.0.4
patch
| ||
v2.0.3
patch
| ||
v2.1.5
patch
| ||
v2.1.4
patch
| ||
v2.1.3
patch
| ||
v2.1.2
patch
| ||
v2.0.2
patch
| ||
v2.1.1
patch
| ||
v2.0.1
patch
| ||
v1.0.1
patch
|
v1.0.1
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
v2.1.0
minor
| ||
v2.0.0
major
| ||
v2.0.0-beta.1
pre
| ||
v1.0.0
major
| ||
v0.3.2
patch
|
v0.3.2
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
v0.3.1
patch
| ||
v0.3.0
minor
2 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev | ||
v0.2.1
patch
2 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev |
v0.2.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v0.2.0
minor
5 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev | ||
v0.1.6
patch
5 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev |
v0.1.6
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v0.1.5
patch
5 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev | ||
v0.1.4
patch
6 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev
CVE-2024-52305
GHSA-cgr4-c233-h733
Nov 13, 2024
UnoPim Stored XSS : Cookie hijacking through Create User function
Medium
Network
Low
None
None
SummaryA vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. Details
PoCThe below link is a private YouTube video for PoC. https://youtu.be/5j8owD0--1A ImpactThe stored XSS can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
Fixed in
0.1.5
References Updated Nov 13, 2024 · Source: OSV.dev | ||
v0.1.3
patch
7 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev
CVE-2024-52305
GHSA-cgr4-c233-h733
Nov 13, 2024
UnoPim Stored XSS : Cookie hijacking through Create User function
Medium
Network
Low
None
None
SummaryA vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. Details
PoCThe below link is a private YouTube video for PoC. https://youtu.be/5j8owD0--1A ImpactThe stored XSS can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
Fixed in
0.1.5
References Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-50637
GHSA-hv6m-qj65-26q3
Nov 06, 2024
UnoPim Cross-site Scripting vulnerability
Medium
Network
Low
None
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
Fixed in
0.1.4
References Updated Nov 06, 2024 · Source: OSV.dev | ||
v0.1.2
patch
7 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev
CVE-2024-52305
GHSA-cgr4-c233-h733
Nov 13, 2024
UnoPim Stored XSS : Cookie hijacking through Create User function
Medium
Network
Low
None
None
SummaryA vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. Details
PoCThe below link is a private YouTube video for PoC. https://youtu.be/5j8owD0--1A ImpactThe stored XSS can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
Fixed in
0.1.5
References Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-50637
GHSA-hv6m-qj65-26q3
Nov 06, 2024
UnoPim Cross-site Scripting vulnerability
Medium
Network
Low
None
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
Fixed in
0.1.4
References Updated Nov 06, 2024 · Source: OSV.dev | ||
v0.1.1
patch
7 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev
CVE-2024-52305
GHSA-cgr4-c233-h733
Nov 13, 2024
UnoPim Stored XSS : Cookie hijacking through Create User function
Medium
Network
Low
None
None
SummaryA vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. Details
PoCThe below link is a private YouTube video for PoC. https://youtu.be/5j8owD0--1A ImpactThe stored XSS can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
Fixed in
0.1.5
References Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-50637
GHSA-hv6m-qj65-26q3
Nov 06, 2024
UnoPim Cross-site Scripting vulnerability
Medium
Network
Low
None
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
Fixed in
0.1.4
References Updated Nov 06, 2024 · Source: OSV.dev | ||
v0.1.0
initial
7 CVEs
CVE-2025-55745
GHSA-74rg-6f92-g6wx
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
Network
Low
Low
SummaryDescription:
DetailsA basic test for CSV Injection is using The same method can be used to run arbitrary code on the victim's machine. For example the below code will download and execute a malicious script to create a reverse TCP connection to the attacker's machine. Payload:
shell.ps1:
PoC:
Please note that if this is replicated on version starting from Office 2021:
Follow these steps:
Go to Platform Details: Replicated this on Office 2021 on Windows 11. POC video link: https://drive.proton.me/urls/3TP1QEMXNC#2PAy7OkVqdP3 ImpactWhen the victim opens the CSV, the injected formula which fetches a reverse shell script written in Powershell from attacker's server and executes it. This creates a reverse shell connection from victim's device to attacker's allowing an attacker to perform any action on the victim's device. Recommendation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55741
GHSA-8p2f-fx4q-75cx
Aug 22, 2025
UnoPim has Broken Access Control
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
SummaryIn Unopim, it is possible to create roles and choose the privileges. However, users without the “Delete” privilege for Products cannot delete a single product via the standard endpoint (expected behavior), but can still delete products via the mass-delete endpoint, even when the request contains only one product ID. Severity: High CVSS Score 8.1 (CVSS 3.1 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) Category: Broken Access Control / Missing Authorization (OWASP A01:2021) Impact: Unauthorized product deletion -> data loss, possible business disruption Affected BehaviorSingle delete (enforced):
DELETE Mass delete (not enforced):
POST PoCA video was captured in Burp Suite for a proof of concept. The cookies were used directly from Burp Suite and rendered the My Account page to prove what cookies belong to what users. The video PoC is listed in references. ImpactUnauthorized product deletion -> data loss, possible business disruption Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
v0.2.1
v0.3.0
Fixed in
0.3.1
References
Updated Aug 22, 2025 · Source: OSV.dev
CVE-2025-55744
GHSA-287x-6r2h-f9mw
Aug 21, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Medium
Network
Low
None
None
SummarySome of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
DetailsCSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either PoC
POC Video link: https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ
ImpactAttacker can perform action on behalf of the victim as this happens on the victim's browser provide the victim is already authenticated to the application. Attacker can use an image tag to send the GET request such that when the page is loaded, it'll get executed. As shown in the video POC, the product information can be tampered, create new categories etc. Remediation:
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated Aug 21, 2025 · Source: OSV.dev
CVE-2025-55743
GHSA-v22v-xwh7-2vrm
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
Network
Low
High
None
Summary:Affected Functionality: Image upload at User creation
Endpoint: DetailsThe image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The .php file when accessed through the link runs the code we provided inside the file. Modified part of the multipart request body:
PoC
Likewise a reverse shell code ( reverse shell of other languages ) can be executed to create a connection to attacker controlled system. ImpactEvery user in the dashboard is allowed to change their profile picture, thus allowing any of these users to execute malicious actions at the Server level. Usually a server might host multiple applications, allowing execution of system commands allows complete control of the system. The impact of an RCE vulnerability can be full system compromise, access to database and filesystem, access other sensitive devices on the network. Please see the POC video: https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn Recommendation:Extension Validation: Whitelist allowed extensions. ( use Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References Updated May 28, 2026 · Source: OSV.dev
CVE-2025-55742
GHSA-xr97-25v7-hc2q
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
6.8
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
High
SummaryAffected Functionality: User creation
Endpoint: Detailshttps://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19 See the mimetype is checked for validation. Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file. File containing is considered as svg and is sanitized:
Sanitization bypass using MIME type manipulation:
PoCUpload
I changed extension to .html because even though POC.svg successfully bypassed the sanitization.
When accessing the URL, the page didn't render as it should starts with <.
ImpactSuppose another admin visits the image link, the attacker can perform any operation as the victim. The session cookie is marked as http-only that disallow fetching cookies using javascript which is good thing. ( this prevent exfiltrating the cookie but still an attacker can perform any action behalf of the victim ) Example
John doe (default admin ) creates another admin ( victimadmin@test.com )
When the victim-admin logs in and access the endpoint containing stored XSS, the script runs on behalf of victm-admin and the product is created.
Extended POC for performing the action shown in video: POC.html:
// make sure to update the cookies and CSRF tokens in the script to the attacker's. Recommendation: Check file extension: whitelist allowed extensions. Check mime type matches with file extension ( in this case GIF89 ( mime type GIF ) and extension: svg. They are not matching so reject it. Check file extension ( endswith .svg ) and if it is svg then perform the sanitization that is in place. Affected Version: 0.1.6
Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.0
Fixed in
0.2.1
References
Updated Aug 26, 2025 · Source: OSV.dev
CVE-2024-52305
GHSA-cgr4-c233-h733
Nov 13, 2024
UnoPim Stored XSS : Cookie hijacking through Create User function
Medium
Network
Low
None
None
SummaryA vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. Details
PoCThe below link is a private YouTube video for PoC. https://youtu.be/5j8owD0--1A ImpactThe stored XSS can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
Fixed in
0.1.5
References Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-50637
GHSA-hv6m-qj65-26q3
Nov 06, 2024
UnoPim Cross-site Scripting vulnerability
Medium
Network
Low
None
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies. Affected versions
v0.1.0
v0.1.1
v0.1.2
v0.1.3
Fixed in
0.1.4
References Updated Nov 06, 2024 · Source: OSV.dev |