Impact
A flaw was found in Webkul Bagisto, affecting versions up to 2.4.4, where by manipulating the rma_qty, resolution_type, or rma_reason_id parameters in the /customer/account/rma/store request an attacker can force the application to follow an unintended behavioral workflow. The vulnerability is described as user‑controlled behavior enforcement and is known to be exploitable remotely. The weakness falls under CWE‑840, indicating insecure default or hardcoded settings, and CWE‑841, pointing to excessive permissions or overly permissive access controls. Without additional vendor data it is unclear what specific actions an attacker can perform, but the described intent suggests unauthorized operational behavior or elevated capabilities within the application.
Affected Systems
The affected product is Webkul Bagisto. All installations of version 2.4.4 or earlier that expose the /customer/account/rma/store endpoint are susceptible. The vendor states that some of the identified issues have been addressed and remaining ones are slated for future releases, meaning that systems running the latest version may no longer be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the public disclosure and the statement that the exploit is now public indicate that attackers could reason it is worthwhile to target vulnerable instances. The attack vector is remote: an attacker only needs to craft a web request containing the vulnerable parameters. No special conditions are noted, so the exploitability appears straightforward for an attacker with network or internet exposure to the target store.
OpenCVE Enrichment