Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser. This vulnerability is fixed in 2.3.8.
References
| Link | Resource |
|---|---|
| https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346 | Exploit Vendor Advisory |
| https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-10-16 19:15
Updated : 2025-10-22 16:55
NVD link : CVE-2025-62418
Mitre link : CVE-2025-62418
CVE.ORG link : CVE-2025-62418
JSON object : View
Products Affected
webkul
- bagisto
