CVE-2026-102630
4.7 MEDIUMpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-348
Public exploit & PoC references
- https://github.com/unopim/unopim
- https://github.com/unopim/unopim/blob/v2.1.0/bootstrap/app.php#L24
- https://github.com/unopim/unopim/blob/v2.1.0/packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php#L9
- https://github.com/unopim/unopim/commit/77e33618df5ba82fc9c9a32d137368e5bbe5ac9c
- https://github.com/unopim/unopim/releases/tag/v2.0.1
- https://github.com/unopim/unopim/releases/tag/v2.1.1
All references
- https://github.com/unopim/unopim
- https://github.com/unopim/unopim/blob/v2.1.0/bootstrap/app.php#L24
- https://github.com/unopim/unopim/blob/v2.1.0/packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php#L9
- https://github.com/unopim/unopim/commit/77e33618df5ba82fc9c9a32d137368e5bbe5ac9c
- https://github.com/unopim/unopim/releases/tag/v2.0.1
- https://github.com/unopim/unopim/releases/tag/v2.1.1
- https://www.vulncheck.com/advisories/unopim-2.0.0-before-2.0.1-and-2.1.0-before-2.1.1-cache-poisoning-via-x-forwarded-host
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100653PoC
- MEDIUMCVE-2026-101277
- MEDIUMCVE-2026-102275PoC
- CRITICALCVE-2026-61682PoC
- MEDIUMCVE-2026-62987PoC
- MEDIUMCVE-2026-80514
- MEDIUMCVE-2026-84718
- MEDIUMCVE-2026-87070
Related by shared AI tags and CWE weakness class. Browse the full archive.