CVE-2024-52305

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-13 16:15

Updated : 2024-11-19 18:04


NVD link : CVE-2024-52305

Mitre link : CVE-2024-52305

CVE.ORG link : CVE-2024-52305


JSON object : View

Products Affected

webkul

  • unopim
CWE
CWE-616

Incomplete Identification of Uploaded File Variables (PHP)

CWE-692

Incomplete Denylist to Cross-Site Scripting