PT-2025-34443 · Laravel+1 · Laravel+1

0Xcharb

·

Published

2025-08-22

·

Updated

2025-08-22

·

CVE-2025-55741

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: UnoPim versions 0.3.0 and earlier
Description: UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Users lacking the necessary Delete privilege for products can bypass access controls by submitting requests to the mass-delete endpoint, enabling unauthorized product deletion. This can lead to potential data loss and business disruption.
Recommendations: Update to version 0.3.1 or later.

Exploit

Fix

LPE

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-55741
GHSA-8P2F-FX4Q-75CX

Affected Products

Laravel
Unopim