Impact
A flaw exists in the RMA State Validation component of Webkul Bagisto that allows manipulation of the /customer/account/rma/update-status endpoint, thereby forcing an unintended behavioral workflow. The weakness involves deserialization of untrusted data (CWE-840) and failure to restrict access to the endpoint (CWE-841), making it possible for an attacker to change the status of a Return Merchandise Authorization without consent.
Affected Systems
Webkul Bagisto versions up to 2.4.4 are impacted. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and although no EPSS score is available, the vulnerability has been publicly disclosed and can be triggered remotely. The vendor has acknowledged the issue and is planning a fix in forthcoming releases, but the vulnerability is not yet listed in the CISA KEV catalog. In the absence of proof of exploitation, the risk remains moderate, though any successful call to the vulnerable endpoint could upset inventory and financial records.
OpenCVE Enrichment