Impact
The vulnerability resides in the /admin/customers/search component of Webkul Bagisto version 2.4.4 and earlier. The flaw allows an attacker to manipulate the Query argument, enabling the disclosure of sensitive customer data. The weakness is categorized as CWE-200 and CWE-284, indicating improper information exposure and insufficient authorization. Because the attacker can trigger the flaw remotely, the confidentiality of customer records is compromised.
Affected Systems
This issue affects Webkul Bagisto customers up to and including version 2.4.4. The vendor acknowledges that the problems were identified prior to public notification and that some items have already been addressed with plans to resolve the remaining items in future releases. Any deployment using Bagisto 2.4.4 or earlier is potentially susceptible until a confirmed patch is applied.
Risk and Exploitability
The CVSS base score is 5.1, reflecting moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires remote access via the web interface and can be carried out by sending a crafted request to the query endpoint. Attackers can gain unauthorized visibility into customer information without needing privileged credentials, and the availability impact is negligible. Given the lack of a publicly available patch, the best mitigation involves applying the latest product update when it becomes available and implementing defensive checks on the affected endpoint.
OpenCVE Enrichment