Impact
In Bagisto version 2.4.4 and earlier, the RMA message handling routine accepts a Message parameter that is rendered without proper sanitization. An attacker supplied payload can inject arbitrary JavaScript when the RMA message page is displayed. An exploited payload can steal session cookies, hijack user sessions, deface the site, or launch further attacks such as credential phishing. The vulnerability is a classic client‑side injection weakness.
Affected Systems
The flaw exists in Webkul Bagisto, specifically in the customer account RMA send‑message component. All installations running Bagisto 2.4.4 or older are affected; newer releases are not mentioned as vulnerable.
Risk and Exploitability
With a CVSS score of 5.1, the severity is in the medium range. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, indicating that the exploitation probability is not documented as high yet. However, the exploit code is publicly available and the attack can be performed from any web client that has access to the RMA message endpoint, which makes remote exploitation straightforward. The lack of vendor‑level mitigation in current releases increases the risk for users still on affected versions.
OpenCVE Enrichment