Impact
UnoPim versions prior to 2.0.1 and 2.1.1 accept the X-Forwarded-Host header from any connecting client as if the client were a trusted proxy, with no validation. This allows an unauthenticated attacker to set the header to any arbitrary value, causing the application to embed attacker‑controlled JavaScript asset URLs in its admin layout pages. When these pages are cached by shared proxies, subsequent administrators who view the cached content will execute the injected code in the context of their authenticated sessions, effectively granting the attacker virtual access to administrative consoles.
Affected Systems
The vulnerability affects the "UnoPim" product developed by Webkul. All releases before 2.0.1 and before 2.1.1 are impacted. Version 2.0.1 and 2.1.1 contain the mitigating changes.
Risk and Exploitability
The CVSS score of 2.3 indicates low base severity, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires only an unauthenticated HTTP request with a crafted X-Forwarded-Host header, the likelihood of exploitation in the absence of protective controls is modest; however, shared proxy caching can amplify the impact by propagating injected code to many administrators. There is no indicator of a higher exploit probability (EPSS is not available). The main attack vector is the trusted proxy header and the caching of admin pages.
OpenCVE Enrichment