7.3
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1.
Basic Information
ID
CVE-2025-55743
Source
GitHub_M
Published
Aug 21, 2025 at 15:45
Affected Product
Vendor
unopim
Product
unopim
Version
< 0.2.1
Affected Versions
unopim unopim < 0.2.1