CVE-2023-36238: Medium severity webkul bagisto vulnerability
Published Mar 13, 2024
·Updated
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.0 allows an attacker to obtain sensitive information via the invoice ID parameter.
Other sources
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
— MITRE
Affected Software
2 affected componentsFixes available
composer/bagisto/bagisto<1.3.2
1.3.2
Webkul Bagisto=1.5.1
Event History
Mar 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-36238?
CVE-2023-36238 has a medium severity level due to its potential to expose sensitive information.
2
What versions of Bagisto are affected by CVE-2023-36238?
CVE-2023-36238 affects Bagisto versions 1.5.0 and 1.5.1.
3
How do I fix CVE-2023-36238?
To fix CVE-2023-36238, upgrade Bagisto to version 1.5.2 or later.
4
What type of vulnerability is CVE-2023-36238?
CVE-2023-36238 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
5
What can an attacker do with CVE-2023-36238?
An attacker can exploit CVE-2023-36238 to access sensitive information via the invoice ID parameter.