CVE-2019-16403

In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
References
Link Resource
https://github.com/bagisto/bagisto/issues/749 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-09-18 12:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-16403

Mitre link : CVE-2019-16403

CVE.ORG link : CVE-2019-16403


JSON object : View

Products Affected

webkul

  • bagisto
CWE
CWE-639

Authorization Bypass Through User-Controlled Key