Executive brief
Webkul Bagisto is an open-source e-commerce platform that manages online stores and transactions. A flaw in the add-to-cart API and downloadable fulfillment components allows remote attackers to access sensitive information without proper authorization, potentially exposing customer data or business information.
Technical details
This vulnerability is an information disclosure issue affecting the add-to-cart API and downloadable fulfillment components in Bagisto 2.4.9. The flaw allows remote attackers to retrieve sensitive data via improper input handling or insufficient access controls in these APIs. No authentication is required to exploit this issue; the attack vector is network-based. Attackers can obtain sensitive information that should not be publicly accessible, including potentially customer details or order information. A patch may be available in newer versions of Bagisto.
Affected products
- Webkul Bagisto 2.4.9
Timeline
- 2026-09-15: disclosed