GHSA-29mf-w486-v3vc

Suggest an improvement
Source
https://github.com/advisories/GHSA-29mf-w486-v3vc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-29mf-w486-v3vc/GHSA-29mf-w486-v3vc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-29mf-w486-v3vc
Aliases
Published
2025-10-10T21:31:15Z
Modified
2025-10-17T19:26:31Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:H CVSS Calculator
Summary
Bagisto is vulnerable to XSS through Admin Panel's product creation path
Details

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-13T13:34:11Z",
    "nvd_published_at": "2025-10-10T19:15:38Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / bagisto/bagisto

Package

Name
bagisto/bagisto
Purl
pkg:composer/bagisto/bagisto

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.6
Fixed
2.3.7

Affected versions

2.*
2.3.6
v2.*
v2.3.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-29mf-w486-v3vc/GHSA-29mf-w486-v3vc.json"