CVE-2025-56426: Command Injection
Published Oct 9, 2025
·Updated
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.
Affected Software
2 affected components
Webkul Bagisto
Webkul Bagisto=2.3.6
Event History
Oct 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56426?
CVE-2025-56426 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-56426?
To fix CVE-2025-56426, update WebKul Bagisto to the latest version where the vulnerability has been addressed.
3
What does CVE-2025-56426 affect?
CVE-2025-56426 affects WebKul Bagisto version 2.3.6, specifically through the Cart/Checkout API endpoint.
4
What type of attack is possible with CVE-2025-56426?
CVE-2025-56426 allows a remote attacker to execute arbitrary code by manipulating the quantity inputs during price calculations.
5
Who is impacted by CVE-2025-56426?
All users and administrators of WebKul Bagisto version 2.3.6 are impacted by CVE-2025-56426.