CVE-2026-102630
Deferred Deferred - Pending Action

Open Redirect in UnoPim via X-Forwarded-Host Header

Vulnerability report for CVE-2026-102630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
unopim unopim to 2.0.1|start_including=2.1.1 (exc)
unopim unopim to 2.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-348 The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects UnoPim versions before 2.0.1 and 2.1.1. It allows unauthenticated attackers to inject arbitrary origins into admin layout pages by exploiting the X-Forwarded-Host header without validation. Attackers can redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators may execute attacker-supplied code in their authenticated sessions.

Detection Guidance

Check UnoPim admin layout pages for unexpected JavaScript asset loading from external origins. Inspect HTTP headers for X-Forwarded-Host values set by clients. Review cached responses from shared proxies for injected origins. Use network monitoring tools to detect unusual Host or X-Forwarded-Host header usage.

Impact Analysis

If you use an affected UnoPim version, attackers could manipulate admin pages to load malicious JavaScript from their server. This could lead to unauthorized actions being performed by administrators, data theft, or full frontend takeover. The impact depends on whether shared proxies are used and if responses are cached.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive admin functions, potentially exposing personal data. This may violate GDPR (data protection) and HIPAA (health information privacy) requirements for access controls and data security. Compliance could be impacted if attackers exfiltrate regulated data.

Mitigation Strategies

Upgrade UnoPim to version 2.0.1 or 2.1.1 or later. Configure TRUSTED_PROXIES to restrict trusted proxies (default to 127.0.0.1). Set TRUSTED_HOSTS to APP_URL to prevent header spoofing. Verify URL generation uses config('app.url') instead of request headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart