PT-2025-34235 · Laravel+1 · Laravel+1

Sn1P3Rt3S7

·

Published

2025-08-21

·

Updated

2025-08-21

·

CVE-2025-55742

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: UnoPim versions prior to 0.2.1
Description: UnoPim, an open-source Product Information Management (PIM) system built on the Laravel framework, contains a stored cross-site scripting vulnerability. The vulnerability is due to an SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. An attacker can exploit this issue by uploading a specially crafted SVG file with a manipulated MIME type, potentially allowing them to execute arbitrary JavaScript code on behalf of other administrators. The session cookie is marked as http-only, which prevents cookie exfiltration via JavaScript, but does not prevent the attacker from performing actions as the victim.
Recommendations: Versions prior to 0.2.1: Check file extensions and whitelist allowed extensions. Versions prior to 0.2.1: Verify that the MIME type matches the file extension. Versions prior to 0.2.1: If the file extension is SVG, ensure proper sanitization is performed.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55742
GHSA-XR97-25V7-HC2Q

Affected Products

Laravel
Unopim