Impact
The vulnerability resides in the /admin/reporting/sales component of Webkul Bagisto up to version 2.4.4, where an attacker can manipulate the request to bypass the platform's authorization checks. The flaw corresponds to CWE‑285 and CWE‑639, allowing an unauthenticated or low‑privileged user to retrieve sales reporting data that should be restricted to privileged administrators. Although the flaw does not enable code execution or compromise system integrity, it permits unauthorized disclosure of potentially sensitive business information, representing a data‑exposure risk.
Affected Systems
Webkul Bagisto 2.4.4 and earlier contain the vulnerable code. The issue affects the backend reporting endpoint located at /admin/reporting/sales and does not extend to other Webkul products.
Risk and Exploitability
The CVSS base score of 5.3 places the vulnerability in the medium severity range. EPSS is not available, and the flaw is not listed in the CISA KEV catalog. Attackers can trigger the bypass remotely by sending crafted requests to the reporting endpoint over the network. No additional privileges or system compromise are required beyond the initial web‑side request, making the exploitation straightforward for anyone with internet or internal access to the backend. The risk is moderate in environments where the endpoint is exposed without proper authentication safeguards.
OpenCVE Enrichment