Unauthorized Product Deletion Vulnerability in UnoPim PIM System
CVE-2025-55741
8.1HIGH
What is CVE-2025-55741?
UnoPim, an open-source Product Information Management (PIM) system built on the Laravel framework, suffers from a serious authorization bypass issue. Users without the appropriate Delete privileges can exploit the mass-delete endpoint to delete products unauthorizedly, potentially resulting in significant data loss and business disruption. This vulnerability affects all versions prior to 0.3.1, and urgent updates are recommended to secure your system. No known workarounds are available.
Affected Version(s)
unopim < 0.3.1