Impact
The vulnerability arises from insecure handling of the ID argument in the /admin/customers component of the Backend Customer Behavior Data Endpoint. Manipulating this argument enables an attacker to bypass proper privilege checks, effectively granting unauthorized administrative privileges. This flaw is classified as an improper privilege management weakness, mapping to CWE-266 and CWE-269.
Affected Systems
The issue affects all Webkul Bagisto installations up to and including version 2.4.4. The vendor issued an internal assessment confirming that the problem has been partially addressed, with remaining items slated for future releases. No specific version beyond 2.4.4 is listed as fixed, so any deployment using the affected range remains vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the exploit is documented as publicly available, suggesting that an attacker can reach the vulnerable endpoint from a remote location. EPSS data is not available, but the absence of a KEV listing does not diminish the risk of exploitation. Given the remote nature of the attack vector and the potential for privilege escalation, administrators should treat this as a moderate risk that warrants prompt remediation.
OpenCVE Enrichment