Reflected Cross-Site Scripting Vulnerability in Bagisto by Bagisto
CVE-2025-40675
5.1MEDIUM
What is CVE-2025-40675?
A reflected cross-site scripting (XSS) vulnerability exists in Bagisto version 2.0.0, permitting attackers to inject and execute harmful JavaScript code in victims' browsers. By crafting a malicious URL containing a 'query' parameter used in the '/search' functionality, attackers can manipulate user sessions, potentially stealing sensitive data such as session cookies or conducting actions on behalf of the unwitting user. This flaw underscores the necessity for robust input validation and sanitization within web applications.
Affected Version(s)
Bagisto 2.2.2