A vulnerability was detected in Webkul Bagisto up to 2.4...
Low severity
Unreviewed
Published
Sep 28, 2026
to the GitHub Advisory Database
•
Updated Sep 28, 2026
Description
Published by the National Vulnerability Database
Sep 28, 2026
Published to the GitHub Advisory Database
Sep 28, 2026
Last updated
Sep 28, 2026
A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
References