Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser. This vulnerability is fixed in 2.3.8.
References
| Link | Resource |
|---|---|
| https://github.com/bagisto/bagisto/security/advisories/GHSA-67px-r26w-598x | Exploit Vendor Advisory |
| https://github.com/bagisto/bagisto/security/advisories/GHSA-67px-r26w-598x | Exploit Vendor Advisory |
Configurations
History
22 Oct 2025, 17:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:webkul:bagisto:2.3.7:*:*:*:*:*:*:* | |
| First Time |
Webkul bagisto
Webkul |
|
| References | () https://github.com/bagisto/bagisto/security/advisories/GHSA-67px-r26w-598x - Exploit, Vendor Advisory |
17 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bagisto/bagisto/security/advisories/GHSA-67px-r26w-598x - |
16 Oct 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-16 19:15
Updated : 2025-10-22 17:21
NVD link : CVE-2025-62415
Mitre link : CVE-2025-62415
CVE.ORG link : CVE-2025-62415
JSON object : View
Products Affected
webkul
- bagisto
