ZeroHour

CVE-2024-50637

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p32
Published
()
Modified
Description

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.

Vendors
webkul
Products
unopim
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.