CSV Injection Vulnerability in UnoPim Product Information Management System
CVE-2025-55745

2.5LOW

Key Information:

Vendor

Unopim

Status
Vendor
CVE Published:
22 August 2025

What is CVE-2025-55745?

UnoPim, an open-source Product Information Management (PIM) system based on the Laravel framework, has a vulnerability in its Quick Export feature that can be exploited via CSV injection. This allows an attacker to insert malicious content into CSV files, which, when processed by applications like Microsoft Excel, can execute arbitrary code. This phenomenon, also known as formula injection, can enable attackers to take control of the victim's device, potentially facilitating unauthorized access and the establishment of a reverse shell. Users are strongly advised to upgrade to version 0.3.1 or later to mitigate this security risk.

Affected Version(s)

unopim < 0.3.1

References

CVSS V4

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55745 : CSV Injection Vulnerability in UnoPim Product Information Management System