CVE-2026-102630 Details
Description
UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.
A vulnerability exists in UnoPim versions prior to 2.0.1 and 2.1.1, where the application trusts all connecting clients as proxies and accepts the X-Forwarded-Host header without proper validation. This flaw allows unauthenticated attackers to inject arbitrary origins into admin layout pages. By manipulating the X-Forwarded-Host header, attackers can redirect the loading of JavaScript assets to their own servers. If these responses are cached by shared proxies, any subsequent actions by administrators could trigger the execution of the injected code within their authenticated sessions.
Users can upgrade to UnoPim versions 2.0.1 or 2.1.1, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| UnoPim | >= 2.0.0, < 2.0.1 (semver) >= 2.1.0, < 2.1.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion