PT-2026-6370 · Packagist · Bagisto/Bagisto

Published

2026-01-02

·

Updated

2026-01-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Summary

SSTI when normal customer orders any product in add address step can inject value run in admin view.

Details

As normal user
  1. Go to http://127.0.0.1:8000/
  2. Add order to cart and continue to checkout
  3. In step of add address inject this value {{7*7}} in any input
As admin
  1. Go to http://127.0.0.1:8000/admin/sales/orders
  2. And notice the vlaue appear in admin view 49
As normal user 3. Go to add address normally http://127.0.0.1:8000/customer/account/addresses/create and inject {{7*7}} on it and will notice it appear 49 image

PoC

Impact

  • Can lead to RCE

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-5J4H-4F72-QPM6

Affected Products

Bagisto/Bagisto