Remote Code Execution Vulnerability in WebKul Bagisto E-Commerce Platform
CVE-2025-56426
6.5MEDIUM
What is CVE-2025-56426?
A vulnerability in WebKul Bagisto version 2.3.6 allows remote attackers to execute arbitrary code through the Cart/Checkout API endpoint. This issue arises because the price calculation logic does not properly validate quantity inputs, potentially leading to manipulation of the application’s behavior by entering malicious data.
