CVE-2024-52305

MEDIUM

UnoPim < 0.1.5 - Stored Cross-Site Scripting via SVG Profile Image Upload

Title source: llm
STIX 2.1

Description

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

Scores

CVSS v3 6.5
EPSS 0.0018
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-616 CWE-692
Status published
Products (2)
unopim/unopim 0 - 0.1.5Packagist
webkul/unopim < 0.1.5
Published Nov 13, 2024
Tracked Since Feb 18, 2026