Junglewise Threat Intelligence

CVE-2025-55743: UnoPim arbitrary file upload in user creation image upload

CVE-2025-55743 · Severity: high · CVSS 4 · Published 2025-08-21

Technologies: unopim/unopim (Packagist). Vendors: Packagist.

Executive brief

UnoPim, an open-source Product Information Management system, is vulnerable to a security flaw that allows users with administrative dashboard access to take over the underlying server. By bypassing simple file upload checks during user profile creation, an attacker can upload and execute malicious scripts. This could lead to a total system compromise, including unauthorized access to the database, sensitive files, and other devices on the corporate network.

Technical details

UnoPim (up to version 0.2.0) contains an unrestricted file upload vulnerability in the user creation endpoint (/admin/settings/users/create). The application only performs client-side validation for file types, allowing an attacker to intercept the request and upload a PHP shell by modifying the file extension and content-type. Once uploaded, the file is stored in a web-accessible directory, enabling the attacker to execute arbitrary system commands or establish a reverse shell. This vulnerability is mitigated by the requirement for high privileges (dashboard access), but it allows for full server compromise. A fix is available in version 0.2.1.

Affected products

  • UnoPim UnoPim <= 0.2.0

Timeline

  • 2025-08-21: disclosed
  • 2025-08-21: advisory
  • 2025-08-21: patched: Fixed in version 0.2.1

References

Related threats