Impact
Authenticated users can send a quantity parameter that is not validated in the add‑to‑cart route, causing the order total to be calculated below the true price of shippable goods. This flaw is an input validation weakness (CWE-20) that can be exploited to create fraudulent orders and result in financial loss for the merchant.
Affected Systems
Webkul Bagisto version 2.4.9 is affected. No other product or version information is supplied by the CNA. The issue exists in the add‑to‑cart functionality of this e‑commerce application.
Risk and Exploitability
The vulnerability carries a high CVSS score of 8.1 and is not listed in the CISA KEV catalog. EPSS data is not available, so the current exploitation probability cannot be quantified. The flaw requires authentication, indicating the attacker must have valid credentials or compromise an account. Once authenticated, an attacker can manipulate cart totals at will, creating a direct financial impact for the merchant if the fraud is not detected.
OpenCVE Enrichment