CVE-2025-62416 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being…
Medium CVSS: 5.1

CVE-2025-62416

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with product creation privileges to inject arbitrary template expressions that are evaluated by the backend — potentially leading to Remote Code Execution (RCE) on the server. This vulnerability is fixed in 2.3.8.
Vendor
Webkul
Product
Bagisto
CWE
CWE-94
Yayın Tarihi
2025-10-16 19:15:34
Güncelleme
2025-10-22 17:06:55
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar