Impact
The bug in Webkul Bagisto 2.4.9 allows a backend user who holds only the settings.users.edit permission to gain full administrator privileges. The user‑update endpoint does not validate that the actor is authorized to grant a requested role, does not prevent users from assigning a role to themselves, and does not enforce that the requested role’s permission set is a subset of the actor’s own. By sending a request that sets role_id to the Administrator role for their own account, the attacker can elevate privileges and gain access to all admin‑panel functions, including store configuration, payment gateway credentials, and customer personal data.
Affected Systems
Webkul Bagisto 2.4.9 installations with the admin user‑management component enabled. Merchants who have not applied the official patch or upgraded to a version in which the issue is fixed are affected. The vulnerability is specific to this version; newer releases contain the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, classifying it as high severity. EPSS indicates less than 1% exploitation probability, and the flaw is not listed in CISA KEV. Nonetheless, any authenticated user with the minimal settings.users.edit permission can craft a request to the /admin/settings/users/update route to change their own role, granting full administrator rights. The lack of authorization checks makes the attack straightforward for anyone with access to the backend, creating a serious risk for data confidentiality, integrity, and availability if exploited.
OpenCVE Enrichment