PT-2026-72048 · Webkul · Bagisto
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Webkul Bagisto versions prior to 2.4.5
Description
A weakness in the Customer Search component, specifically within the
/admin/customers/search endpoint, allows for remote information disclosure. This occurs when the Query argument is manipulated, enabling an attacker to access sensitive data.Recommendations
Update Webkul Bagisto to version 2.4.5 or later.
As a temporary mitigation, restrict access to the
/admin/customers/search endpoint.Exploit
Fix
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bagisto