Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25455 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1. |
Github GHSA |
GHSA-v22v-xwh7-2vrm | UnoPim vulnerable to remote code execution through Arbitrary File upload |
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unopim
Unopim unopim |
|
| Vendors & Products |
Unopim
Unopim unopim |
Fri, 22 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkul
Webkul unopim |
|
| CPEs | cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul unopim |
|
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1. | |
| Title | UnoPim vulnerable to remote code execution through Arbitrary File upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-21T20:00:06.996Z
Reserved: 2025-08-14T22:31:17.685Z
Link: CVE-2025-55743
Updated: 2025-08-21T19:59:59.600Z
Status : Analyzed
Published: 2025-08-21T16:15:34.467
Modified: 2025-08-22T21:53:47.107
Link: CVE-2025-55743
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:39Z
EUVD
Github GHSA