UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1.
History

Thu, 21 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
Description UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1.
Title UnoPim vulnerable to remote code execution through Arbitrary File upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-21T15:45:32.296Z

Updated: 2025-08-21T20:00:06.996Z

Reserved: 2025-08-14T22:31:17.685Z

Link: CVE-2025-55743

cve-icon Vulnrichment

Updated: 2025-08-21T19:59:59.600Z

cve-icon NVD

Status : Received

Published: 2025-08-21T16:15:34.467

Modified: 2025-08-21T16:15:34.467

Link: CVE-2025-55743

cve-icon Redhat

No data.