CVE-2024-50637

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*

History

24 Jun 2025, 16:56

Type Values Removed Values Added
CPE cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*
First Time Webkul unopim
Webkul
References () https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Unopim/Findings.md - () https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Unopim/Findings.md - Exploit, Third Party Advisory
References () https://github.com/unopim/unopim/releases/tag/v0.1.4 - () https://github.com/unopim/unopim/releases/tag/v0.1.4 - Release Notes
References () https://github.com/unopim/unopim/issues/41 - () https://github.com/unopim/unopim/issues/41 - Issue Tracking, Vendor Advisory

07 Nov 2024, 14:15

Type Values Removed Values Added
Summary UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. ¶¶ The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies. UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.

06 Nov 2024, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-06 17:15

Updated : 2025-06-24 16:56


NVD link : CVE-2024-50637

Mitre link : CVE-2024-50637


JSON object : View

Products Affected

webkul

  • unopim
CWE

No CWE.