CVE-2024-50637

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*

History

24 Jun 2025, 16:56

Type Values Removed Values Added
First Time Webkul unopim
Webkul
References () https://github.com/unopim/unopim/issues/41 - () https://github.com/unopim/unopim/issues/41 - Issue Tracking, Vendor Advisory
References () https://github.com/unopim/unopim/releases/tag/v0.1.4 - () https://github.com/unopim/unopim/releases/tag/v0.1.4 - Release Notes
References () https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Unopim/Findings.md - () https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Unopim/Findings.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*

Information

Published : 2024-11-06 17:15

Updated : 2025-06-24 16:56


NVD link : CVE-2024-50637

Mitre link : CVE-2024-50637

CVE.ORG link : CVE-2024-50637


JSON object : View

Products Affected

webkul

  • unopim
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')