{"id":"CVE-2025-55743","aliases":["GHSA-v22v-xwh7-2vrm"],"url":"https://o3.security/vulnerability/CVE-2025-55743","summary":"UnoPim vulnerable to remote code execution through Arbitrary File upload","details":"UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1.","published":"2025-08-21T15:45:32.296Z","modified":"2026-07-15T01:49:21.781687420Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"unopim/unopim","fixedVersion":"0.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://drive.proton.me/urls/PH1ESMKHMW#4Vxb2KNu3tmn"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55743.json"},{"type":"ADVISORY","url":"https://github.com/unopim/unopim/security/advisories/GHSA-v22v-xwh7-2vrm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55743"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:21.781687420Z"}}