UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1.
History

Sat, 23 Aug 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Unopim
Unopim unopim
Vendors & Products Unopim
Unopim unopim

Fri, 22 Aug 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul unopim
CPEs cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul unopim
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 21 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
Description UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1.
Title UnoPim vulnerable to remote code execution through Arbitrary File upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-21T15:45:32.296Z

Updated: 2025-08-21T20:00:06.996Z

Reserved: 2025-08-14T22:31:17.685Z

Link: CVE-2025-55743

cve-icon Vulnrichment

Updated: 2025-08-21T19:59:59.600Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-21T16:15:34.467

Modified: 2025-08-22T21:53:47.107

Link: CVE-2025-55743

cve-icon Redhat

No data.