UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.
                
            References
                    | Link | Resource | 
|---|---|
| https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ | Exploit | 
| https://github.com/unopim/unopim/security/advisories/GHSA-287x-6r2h-f9mw | Exploit Vendor Advisory | 
Configurations
                    History
                    22 Aug 2025, 21:52
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Webkul Webkul unopim | |
| CPE | cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:* | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.3 | 
| References | () https://drive.proton.me/urls/VXNDKQ4WKR#LpvE777hl8OJ - Exploit | |
| References | () https://github.com/unopim/unopim/security/advisories/GHSA-287x-6r2h-f9mw - Exploit, Vendor Advisory | 
22 Aug 2025, 18:09
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
21 Aug 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-21 16:15
Updated : 2025-08-22 21:52
NVD link : CVE-2025-55744
Mitre link : CVE-2025-55744
CVE.ORG link : CVE-2025-55744
JSON object : View
Products Affected
                webkul
- unopim
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
