Impact
A vulnerability in Webkul Bagisto up to version 2.4.4 allows manipulation of the action argument in the /admin/configuration/cache-management/execute endpoint, leading to an authorization bypass. The attacker can trigger privileged cache‑management operations without proper authentication, potentially altering configuration state or triggering arbitrary server actions that compromise the integrity and availability of the application. The weakness, identified as CWE‑285 and CWE‑639, indicates improper authorization checks within a web interface.
Affected Systems
The issue affects installations of Webkul Bagisto, specifically versions up to and including 2.4.4. The vulnerable functionality resides within the Bagisto Configuration Management component, accessed via the administrative URL /admin/configuration/cache-management/execute. No partial or earlier versions are known to be impacted, and later releases may have addressed the flaw.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, and the vulnerability can be abused remotely without local privileges. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting that publicly known exploits may exist but are not yet confirmed at scale. The attack vector is inferred to be remote web exploitation through crafted HTTP requests to the privileged endpoint, with the primary condition that the user has access to the administrative interface.
OpenCVE Enrichment