PT-2024-35166 · Unopim · Unopim

Yamerooo123

·

Published

2024-11-13

·

Updated

2024-11-19

·

CVE-2024-52305

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions UnoPim versions prior to 0.1.5
Description A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This issue can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place.
Recommendations For versions prior to 0.1.5, update to version 0.1.5 to fix the vulnerability. As a temporary workaround, consider disabling the profile image upload feature in the Create User process until the update is applied. Restrict access to the Create User page to minimize the risk of exploitation. Avoid using the profile image feature in the Create User process until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-52305
GHSA-CGR4-C233-H733

Affected Products

Unopim