Description
UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.
Published: 2026-09-29
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

UnoPim versions prior to 2.0.1 and 2.1.1 accept the X-Forwarded-Host header from any connecting client as if the client were a trusted proxy, with no validation. This allows an unauthenticated attacker to set the header to any arbitrary value, causing the application to embed attacker‑controlled JavaScript asset URLs in its admin layout pages. When these pages are cached by shared proxies, subsequent administrators who view the cached content will execute the injected code in the context of their authenticated sessions, effectively granting the attacker virtual access to administrative consoles.

Affected Systems

The vulnerability affects the "UnoPim" product developed by Webkul. All releases before 2.0.1 and before 2.1.1 are impacted. Version 2.0.1 and 2.1.1 contain the mitigating changes.

Risk and Exploitability

The CVSS score of 2.3 indicates low base severity, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires only an unauthenticated HTTP request with a crafted X-Forwarded-Host header, the likelihood of exploitation in the absence of protective controls is modest; however, shared proxy caching can amplify the impact by propagating injected code to many administrators. There is no indicator of a higher exploit probability (EPSS is not available). The main attack vector is the trusted proxy header and the caching of admin pages.

Generated by OpenCVE AI on September 30, 2026 at 00:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest version of UnoPim (2.0.1 or later for the 2.0.x line, 2.1.1 or later for the 2.1.x line).
  • If an immediate upgrade is impractical, remove or disable the trust‑proxy setting that honors X‑Forwarded‑Host and validate or strip the header before use.
  • Configure intermediate caching proxies to exclude or avoid caching admin pages, or apply cache‑control headers that prevent shared caches from storing these responses.

Generated by OpenCVE AI on September 30, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Unopim
Unopim unopim
Vendors & Products Unopim
Unopim unopim

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.
Title UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwarded-Host
First Time appeared Webkul
Webkul unopim
Weaknesses CWE-348
CPEs cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul unopim
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-29T15:42:20.741Z

Reserved: 2026-09-29T15:25:21.752Z

Link: CVE-2026-102630

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-29T16:17:06.523

Modified: 2026-09-29T16:17:06.670

Link: CVE-2026-102630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:00:09Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source