CSV Injection Vulnerability in UnoPim Product Information Management System
CVE-2025-55745
2.5LOW
What is CVE-2025-55745?
UnoPim, an open-source Product Information Management (PIM) system based on the Laravel framework, has a vulnerability in its Quick Export feature that can be exploited via CSV injection. This allows an attacker to insert malicious content into CSV files, which, when processed by applications like Microsoft Excel, can execute arbitrary code. This phenomenon, also known as formula injection, can enable attackers to take control of the victim's device, potentially facilitating unauthorized access and the establishment of a reverse shell. Users are strongly advised to upgrade to version 0.3.1 or later to mitigate this security risk.
Affected Version(s)
unopim < 0.3.1