Loading vulnerability details…
CVSS v3.1
5.4
EPSS
0.37%
Published
Nov 6, 2024
Modified
Jun 24, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:LWeaknesses (CWE)
Affected Products (1)
References (3)