CVE-2025-55745 Details
Description
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious content into exported CSV files. When the CSV file is opened in spreadsheet applications such as Microsoft Excel, the malicious input may be interpreted as a formula or command, potentially resulting in the execution of arbitrary code on the victim's device. Successful exploitation can lead to remote code execution, including the establishment of a reverse shell. Users are advised to upgrade to version 0.3.1 or later.
A CSV injection vulnerability has been identified in UnoPim versions through 0.3.0, specifically within the Quick Export feature. This vulnerability allows attackers to inject malicious content into exported CSV files. When these files are opened in spreadsheet applications like Microsoft Excel, the injected content can be interpreted as a formula or command, potentially leading to the execution of arbitrary code on the user's device. Successful exploitation could result in remote code execution, including the establishment of a reverse shell connection to the attacker's machine.
Users are advised to upgrade to UnoPim version 0.3.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/unopim/unopim/commit/b25db9496fc147842a519d1dd42ec03c3bf00a34 | [email protected] | Patch |
| https://github.com/unopim/unopim/security/advisories/GHSA-74rg-6f92-g6wx | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1236 | Improper Neutralization of Formula Elements in a CSV File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| webkul unopim | < 0.3.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 25, 2025 | Initial Analysis | [email protected] |
| Aug 22, 2025 | New CVE Received | [email protected] |