Impact
Bagistosite scripting flaw that is caused by client‑side template injection in the create.blade.php file. By registering a malicious first or a Vue.js expression that is later rendered unescaped. When an administrator opens the Create Order page for the affected customer, Vue.js evaluates the expression as live JavaScript, allowing the attacker to run arbitrary code in the administrator's browser.
Affected Systems
The vulnerability affects Webkul's Bagisto e‑commerce platform, for all releases below version 2.4.4. The official patch is provided in the 2.4.4 release, which adds the Vue.js escapes the payload. Sites running older versions of Bagisto are at risk if they allow customer registration and administrators use the front‑end order interface.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. An attacker only needs to create a customer account; no authentication is required to inject code. Exploitation requires an administrator to view the order‑creation page, limiting impact to environments where admin staff use the front‑end interface. The EPSS score of < 1% shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment