Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser. This vulnerability is fixed in 2.3.8.
References
| Link | Resource |
|---|---|
| https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346 | Exploit Vendor Advisory |
| https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346 | Exploit Vendor Advisory |
Configurations
History
22 Oct 2025, 16:55
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346 - Exploit, Vendor Advisory | |
| First Time |
Webkul bagisto
Webkul |
|
| CWE | CWE-79 | |
| CPE | cpe:2.3:a:webkul:bagisto:2.3.7:*:*:*:*:*:*:* |
17 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346 - |
16 Oct 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-16 19:15
Updated : 2025-10-22 16:55
NVD link : CVE-2025-62418
Mitre link : CVE-2025-62418
CVE.ORG link : CVE-2025-62418
JSON object : View
Products Affected
webkul
- bagisto
