CVE-2024-52305
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Nov 13, 2024
CWE ID 692
CWE ID 616
Summary
CVE-2024-52305 is a vulnerability affecting UnoPim, an open-source Product Information Management system based on Laravel. During the Create User process, a flaw allows the creation of a new admin account with the ability to upload a profile image. Malicious SVG files containing embedded scripts can be uploaded, and when the profile image is accessed, the script executes, potentially stealing session cookies. This vulnerability has been addressed in UnoPim version 0.1.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.