Логотип exploitDog
bind:CVE-2024-52305
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52305

Количество 2

Количество 2

nvd логотип

CVE-2024-52305

около 1 года назад

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cgr4-c233-h733

около 1 года назад

UnoPim Stored XSS : Cookie hijacking through Create User function

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-52305

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-cgr4-c233-h733

UnoPim Stored XSS : Cookie hijacking through Create User function

CVSS3: 7.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу