PT-2025-34444 · Unopim+1 · Unopim+1
Sn1P3Rt3S7
·
Published
2025-08-22
·
Updated
2025-08-22
·
CVE-2025-55745
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
UnoPim versions prior to 0.3.1
Description:
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are susceptible to CSV injection, also known as formula injection, in the Quick Export feature. This allows attackers to inject malicious content into exported CSV files. When opened in spreadsheet applications like Microsoft Excel, the malicious input may be interpreted as a formula or command, potentially leading to the execution of arbitrary code on the victim’s device. Successful exploitation can lead to remote code execution, including the establishment of a reverse shell.
Recommendations:
Upgrade to version 0.3.1 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel
Unopim