First published: Wed Sep 18 2019(Updated: )
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webkul Bagisto | <0.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-16403.
The severity of CVE-2019-16403 is high (8.8).
The affected software is Webkul Bagisto before version 0.1.5.
The CWE ID is 639.
To fix CVE-2019-16403, update Webkul Bagisto to version 0.1.5 or above.