CVE-2025-55744
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
21 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
unopim · unopimWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →