PT-2026-73216 · Webkul · Bagisto
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Webkul Bagisto versions prior to 2.4.5
Description
Cross site scripting occurs in the RMA Message Handler component due to the manipulation of the
Message argument within the '/customer/account/rma/send-message' endpoint. This allows for remote exploitation.Recommendations
Update to a version newer than 2.4.4.
Avoid using the
Message argument in the '/customer/account/rma/send-message' endpoint until the update is applied.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bagisto