PT-2025-34444 · Unopim+1 · Unopim+1

Sn1P3Rt3S7

·

Published

2025-08-22

·

Updated

2025-08-22

·

CVE-2025-55745

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: UnoPim versions prior to 0.3.1
Description: UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are susceptible to CSV injection, also known as formula injection, in the Quick Export feature. This allows attackers to inject malicious content into exported CSV files. When opened in spreadsheet applications like Microsoft Excel, the malicious input may be interpreted as a formula or command, potentially leading to the execution of arbitrary code on the victim’s device. Successful exploitation can lead to remote code execution, including the establishment of a reverse shell.
Recommendations: Upgrade to version 0.3.1 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-55745
GHSA-74RG-6F92-G6WX

Affected Products

Office Excel
Unopim