Impact
A flaw in the admin customer detail view of Webkul Bagisto 2.4.4 and earlier allows an attacker to manipulate the customer ID parameter and view customer information without proper authentication. This results in an authorization bypass that can expose private customer data, with the underlying weakness reflected in CWE‑285 and CWE‑639.
Affected Systems
Webkul Bagisto versions up to 2.4.4 are affected. The vulnerability exists in the /admin/customers/view endpoint of the Backend Customer Detail Feature component.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and no EPSS score is available; however, the exploit has been released to the public and may be launched remotely. Attackers need only reach the admin endpoint—no additional elevated rights are required—and can manipulate the ID argument to bypass authentication. Based on the description, it is inferred that this access could serve as a foothold for more advanced attacks, but that inference is not directly stated in the official details. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment