Description
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pmc7-hmmw-g96q | Bagisto vulnerable to Insecure Direct Object Reference (IDOR) |
References
| Link | Providers |
|---|---|
| https://github.com/Ek-Saini/security/blob/main/IDOR-Bagisto |
|
History
Mon, 14 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkul
Webkul bagisto |
|
| CPEs | cpe:2.3:a:webkul:bagisto:1.5.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul bagisto |
Wed, 04 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-04T21:05:46.475Z
Reserved: 2023-06-21T00:00:00.000Z
Link: CVE-2023-36238
Updated: 2024-08-02T16:45:56.194Z
Status : Analyzed
Published: 2024-03-13T21:15:53.813
Modified: 2025-04-14T13:13:25.427
Link: CVE-2023-36238
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA