CVE-2025-55744

MEDIUM

UnoPim < 0.2.1 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
unopim/unopim 0 - 0.2.1Packagist
webkul/unopim < 0.2.1
Published Aug 21, 2025
Tracked Since Feb 18, 2026