Impact
A code flaw in Webkul Bagisto Customer‑Registration Notification Email allows manipulation of the first_name and last_name arguments, causing basic cross‑site scripting that can be triggered remotely. The issue enables an attacker to inject script payloads that execute in a victim’s browser, potentially leading to session hijacking, defacement, or data theft.
Affected Systems
The vulnerability affects Webkul Bagisto versions up to and including 2.4.4. Systems running these releases are impacted regardless of other components, as the vulnerable element is located within the /customer/register file.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable and the bug is not listed in CISA KEV, suggesting no widespread, automated exploitation presently. Nevertheless, the flaw is remotely exploitable and a proof‑of‑concept has been published, increasing the likelihood of targeted attacks. The absence of a public patch means that unmitigated systems remain at risk until a vendor fix is deployed.
OpenCVE Enrichment