Impact
Authenticated users can send a quantity parameter that is not validated in the add‑to‑cart route, causing the order total to be calculated below the true price of shippable goods. This flaw is an input validation weakness (CWE-20) that can be exploited to create fraudulent orders and result in financial loss for the merchant.
Affected Systems
Webkul Bagisto version 2.4.9 is affected. No other product or version information is supplied by the CNA. The issue exists in the add‑to‑cart functionality of this e‑commerce application.
Risk and Exploitability
The vulnerability carries a high CVSS score of 8.1 and an EPSS score of 0.00345, indicating a very low probability of exploitation. The flaw requires authentication, meaning the attacker must have valid credentials or have compromised an account. Once authenticated, an attacker can manipulate cart totals, creating a direct financial impact for the merchant if the fraud is not detected. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment