Impact
An issue in Webkul Bagisto 2.4.9 enables a remote attacker to retrieve sensitive information by interacting with the add‑to‑cart API and the downloadable fulfilment components. The flaw permits disclosure of data that should be protected, potentially including product details, inventory levels, or other internal information. The vulnerability falls under CWE‑639 Information disclosure through system configuration.
Affected Systems
Webkul Bagisto version 2.4.9 is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the exploit can be performed remotely via an application API request, an attacker with network access could potentially launch the attack without needing credentials. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote and that the exploit requires only sending crafted requests to the add‑to‑cart endpoint, making it fairly easy to execute.
OpenCVE Enrichment