Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-50637


UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.


Published

2024-11-06T17:15:20.680

Last Modified

2025-06-24T16:56:35.010

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application webkul unopim < 0.1.4 Yes

References