PT-2024-12551 · Bagisto · Bagisto

Published

2024-02-26

·

Updated

2025-04-11

·

CVE-2023-36237

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bagisto versions prior to 1.5.1
Description The issue allows an attacker to execute arbitrary code via a crafted HTML script, leveraging a Cross Site Request Forgery vulnerability.
Recommendations For versions prior to 1.5.1, update to version 1.5.1 or later to resolve the issue.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-36237
GHSA-7P7Q-FJFW-V3GF

Affected Products

Bagisto