Unauthorized Product Deletion Vulnerability in UnoPim PIM System
CVE-2025-55741

8.1HIGH

Key Information:

Vendor

Unopim

Status
Vendor
CVE Published:
22 August 2025

What is CVE-2025-55741?

UnoPim, an open-source Product Information Management (PIM) system built on the Laravel framework, suffers from a serious authorization bypass issue. Users without the appropriate Delete privileges can exploit the mass-delete endpoint to delete products unauthorizedly, potentially resulting in significant data loss and business disruption. This vulnerability affects all versions prior to 0.3.1, and urgent updates are recommended to secure your system. No known workarounds are available.

Affected Version(s)

unopim < 0.3.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55741 : Unauthorized Product Deletion Vulnerability in UnoPim PIM System