PT-2025-24416 · Bagisto · Bagisto

Published

2025-06-09

·

Updated

2025-06-09

·

CVE-2025-40675

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bagisto version 2.0.0
Description A Reflected Cross-Site Scripting (XSS) issue has been found, allowing an attacker to execute JavaScript code in the victim's browser by sending a malicious URL using the query parameter in the "/search" API endpoint. This can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Recommendations For Bagisto version 2.0.0, consider disabling the search functionality or restricting access to the "/search" endpoint until a patch is available. Avoid using the query parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-40675

Affected Products

Bagisto