{"id":"CVE-2024-50637","aliases":["GHSA-hv6m-qj65-26q3"],"url":"https://o3.security/vulnerability/CVE-2024-50637","summary":"UnoPim Cross-site Scripting vulnerability","details":"UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function.\n\nThe vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies.","published":"2024-11-06T00:00:00Z","modified":"2026-08-12T03:51:46.627078307Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"unopim/unopim","fixedVersion":"0.1.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/unopim/unopim/releases/tag/v0.1.4"},{"type":"WEB","url":"https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Unopim/Findings.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50637.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-50637"},{"type":"REPORT","url":"https://github.com/unopim/unopim/issues/41"},{"type":"PACKAGE","url":"https://github.com/unopim/unopim"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.627078307Z"}}