GHSA-36mw-854w-84x5LowCVSS 2.7

A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of...

Published
September 28, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

🔗 References (10)