CVE-2026-102630 PUBLISHED

UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwarded-Host

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 2.3

Product Status

Vendor unopim
Product unopim
Versions Default: unaffected
  • affected from 2.0.0 to 2.0.1 (excl.)
  • affected from 2.1.0 to 2.1.1 (excl.)

Credits

  • xoreaxeax-nop finder

References

Problem Types

  • Use of Less Trusted Source CWE