CVE-2024-50637
UnoPim Cross-site Scripting vulnerability
6.1
MEDIUM
CVSS 3.1
EPSS 0.37%
Description
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. The vulnerability allows attackers to perform XSS in SVG file extension, which can be used to stealing cookies.
How to fix CVE-2024-50637
To remediate CVE-2024-50637, upgrade the affected package to a fixed version below.
- Packagist/unopim/unopim—upgrade to 0.1.4 or later
Is CVE-2024-50637 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.1.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |