CVE-2024-52305 is a medium-severity vulnerability affecting UnoPim, an open-source Product Information Management system. It allows an authenticated attacker to create a new admin account and upload a malicious SVG file as a profile image. When this image is accessed, an embedded script executes, potentially leading to session cookie theft. The vulnerability has a CVSS score of 4.8 (AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N), indicating it requires high privileges and user interaction, but can result in low confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is fixed in UnoPim version 0.1.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.5CPE matchmatch criteria | cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.