CVE-2025-40675: Reflected Cross-Site Scripting (XSS) in Bagisto
A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40675?
CVE-2025-40675 is classified as a high severity vulnerability due to its potential to execute arbitrary JavaScript in victims' browsers.
How do I fix CVE-2025-40675?
To mitigate CVE-2025-40675, upgrade Bagisto to version 2.2.4 or later where the vulnerability is patched.
What kind of attack does CVE-2025-40675 facilitate?
CVE-2025-40675 facilitates a Reflected Cross-Site Scripting (XSS) attack by using malicious URLs with the 'query' parameter.
Which versions of Bagisto are affected by CVE-2025-40675?
CVE-2025-40675 affects Bagisto versions from 2.0.0 to 2.2.3.
What is the impact of exploiting CVE-2025-40675?
Exploiting CVE-2025-40675 allows attackers to execute malicious scripts in the context of a user's session, potentially compromising sensitive information.