Bagisto is vulnerable to XSS through Admin Panel's product creation path
High severity
GitHub Reviewed
Published
Oct 10, 2025
to the GitHub Advisory Database
•
Updated Oct 13, 2025
Description
Published by the National Vulnerability Database
Oct 10, 2025
Published to the GitHub Advisory Database
Oct 10, 2025
Reviewed
Oct 13, 2025
Last updated
Oct 13, 2025
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.
References