CVE-2025-55744

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*

History

22 Aug 2025, 21:52

Type Values Removed Values Added
First Time Webkul
Webkul unopim
References () https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ - () https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ - Exploit
References () https://github.com/unopim/unopim/security/advisories/GHSA-287x-6r2h-f9mw - () https://github.com/unopim/unopim/security/advisories/GHSA-287x-6r2h-f9mw - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*

22 Aug 2025, 18:09

Type Values Removed Values Added
Summary
  • (es) UnoPim es un sistema de gestión de información de productos (PIM) de código abierto basado en el framework Laravel. En versiones anteriores a la 0.2.1, algunos endpoints de la aplicación eran vulnerables a Cross site Request forgery (CSRF). Esta vulnerabilidad se corrigió en la 0.2.1.

21 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 16:15

Updated : 2025-08-22 21:52


NVD link : CVE-2025-55744

Mitre link : CVE-2025-55744

CVE.ORG link : CVE-2025-55744


JSON object : View

Products Affected

webkul

  • unopim
CWE
CWE-352

Cross-Site Request Forgery (CSRF)