Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as a formula. This allows an attacker to supply a CSV field (e.g., product name) that contains a formula which may be evaluated by a victim’s spreadsheet application — potentially leading to data exfiltration and remote command execution (via older Excel exploits / OLE/cmd constructs or Excel macros). This vulnerability is fixed in 2.3.8.
References
| Link | Resource |
|---|---|
| https://github.com/bagisto/bagisto/security/advisories/GHSA-jqrp-58fv-w8cq | Exploit Vendor Advisory |
| https://github.com/bagisto/bagisto/security/advisories/GHSA-jqrp-58fv-w8cq | Exploit Vendor Advisory |
Configurations
History
22 Oct 2025, 17:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Webkul bagisto
Webkul |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| References | () https://github.com/bagisto/bagisto/security/advisories/GHSA-jqrp-58fv-w8cq - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:webkul:bagisto:2.3.7:*:*:*:*:*:*:* |
17 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bagisto/bagisto/security/advisories/GHSA-jqrp-58fv-w8cq - |
16 Oct 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-16 19:15
Updated : 2025-10-22 17:00
NVD link : CVE-2025-62417
Mitre link : CVE-2025-62417
CVE.ORG link : CVE-2025-62417
JSON object : View
Products Affected
webkul
- bagisto
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
