Search Results (Refine Search)
- CPE Product Version: cpe:/a:webkul:bagisto:0.1.1
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2023-36236 |
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. Published: January 16, 2024; 5:15:37 PM -0500 |
V3.1: 4.8 MEDIUM V2.0:(not available) |
CVE-2019-16403 |
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers. Published: September 18, 2019; 8:15:11 AM -0400 |
V3.1: 8.8 HIGH V2.0: 6.5 MEDIUM |