PT-2024-35166 · Unopim · Unopim
Yamerooo123
·
Published
2024-11-13
·
Updated
2024-11-19
·
CVE-2024-52305
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
UnoPim versions prior to 0.1.5
Description
A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This issue can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place.
Recommendations
For versions prior to 0.1.5, update to version 0.1.5 to fix the vulnerability. As a temporary workaround, consider disabling the profile image upload feature in the Create User process until the update is applied. Restrict access to the Create User page to minimize the risk of exploitation. Avoid using the profile image feature in the Create User process until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unopim