GHSA-hjcf-7gf4-hr83HighCVSS 8.1

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

🔗 References (3)